AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code 23%

By Swati Khandelwal11%

7/21/2026, 4:06:00 PM

BS Summary: This article contains 24 faulty reasoning types, including Hasty Generalization, Availability Heuristic, and Appeal to Authority, with Negativity Bias as the most egregious example at 27.1% saturation with 283 hits. Analysis detected 1,972 faulty-reasoning hits from 1,046 analyzed words, generating a BS Score of 36.4% and a BS Rank of 23% (16,868 of 21,887 articles). This article is better (less manipulative) than 77.10% of the article peer group.

Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. 
Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. 
AWS has patched the issue, and no CVE has been assigned to it. 
Kiro's safety model rests on a human clicking "allow." 
The agent can run shell commands, fetch URLs, and edit files, and the design assumes a developer reviews anything risky before it happens. 
That approval step is the security boundary, and the flaw let an attacker slip past it without the developer ever being offered a choice. 
The weak point was the file that tells Kiro which external tools to load. 
Kiro reads its list of Model Context Protocol servers, and the exact command used to start each one, from ~/.kiro/settings/mcp.json. 
When that file changes, Kiro reloads it and launches whatever it describes, on the host, with the developer's privileges. 
At the time of the research, Kiro could write to mcp.json on its own with its fsWrite tool, no approval required, and reload it automatically. 
Anyone who could influence the contents of that file could register a server whose start command was arbitrary code, and it would run the moment Kiro reloaded. 
The developer sees a clean API reference. 
Kiro reads the hidden block as a setup task, writes the malicious server into mcp.json, and reloads. 
Within seconds, the rogue server starts, and the attacker's code is running. 
In Intezer's demo, the payload only phoned home with the machine's hostname, username, and platform every ten seconds, just enough to prove execution. 
The same primitive could run any command available to the developer, enough to steal credentials and source code, plant persistence, or pivot into whatever internal systems they can reach. 
The researchers kept their callback pointed at localhost so no real Kiro users were exposed, and they note the attack is not perfectly reliable: the model is non-deterministic and may summarize the page and ignore the hidden block. 
In their testing, it worked within one or two tries. 
One success is all it takes. 
Kiro did, in some cases, show a pop-up saying the MCP configuration had changed and asking for approval. 
It made no difference. 
The configuration reloaded regardless of what the developer clicked, so the warning offered no real protection. 
The only action the developer ever actually approved was fetching a URL. 
Kiro had been here before 
An agent able to write the file that governs what it is allowed to run has surfaced in Kiro before. 
On Kiro's release day in July 2025, Johann Rehberger of Embrace The Red showed the same mcp.json write-to-execution move: a prompt injection dropped custom code into an MCP settings file and ran it the moment the file saved. 
He flagged a second route too, writing to .vscode/settings.json to allowlist shell commands. 
AWS's response, Kiro 0.1.42, added an approval prompt for those writes, but only in Supervised mode. 
The default Autopilot mode kept writing the file on its own, and that is the mode. 
Intezer's 2026 chain used. 
No CVE was issued then either. 
Others found neighboring versions of the same class. 
Cymulate reported that Kiro would auto-execute code written to .vscode/tasks.json when a folder was opened. 
AWS assigned it CVE-2026-10591 (8.8 under CVSS 3.1, 8.6 under CVSS 4.0) and fixed it in the 0.11 series. 
Intezer's mcp.json chain was still live on versions 0.9.2 (macOS) and 0.10.16 (Ubuntu) when the company reported it in February 2026, and was confirmed patched in v0.11.130. 
AWS's answer was to stop trusting the model's judgment on these files and move the check into the platform. 
Kiro now marks mcp.json, .vscode/tasks.json, the .git directory, and other sensitive files as protected paths, each requiring explicit approval before a write. 
Its own documentation makes the point directly: "Supervised mode is a code review workflow, not a security control." 
The 1.0 release that followed leans harder on the same principle, with a capability-based permissions model that prompts for consent on anything a developer has not already allowed. 
That combination closes the route Intezer took: Intezer confirmed the attack failed in 0.11.130, and, unlike the 2025 fix, the protected-paths check holds in both Autopilot and Supervised mode. 
Intezer reported the flaw through HackerOne on February 11, 2026, and by April 3 AWS said the fix had shipped in its latest release, though it never named the version; the researchers confirmed it themselves in v0.11.130. 
No CVE has been assigned: The Hacker News found none for the finding in the National Vulnerability Database as of July 21, 2026, and AWS published no complete list of affected builds. 
Intezer reported no in-the-wild exploitation, and its testing covered Kiro IDE; it did not establish whether the separate Kiro CLI or Web builds shared the flaw. 
Current builds are on the 1.0.x line, with 1.0.165 listed as the latest as of July 21, 2026, and anyone on an older version should update from Kiro's downloads page. 
The Hacker News has reached out to AWS for confirmation of the affected Kiro versions and why no CVE was assigned, and will update this story with any response. 
Over roughly a year, three separate research efforts found the same shape of bug in Kiro: an agent quietly editing the files that decide what it is allowed to execute. 
Kiro is not alone: in December 2025, researchers catalogued more than 30 flaws across AI coding tools, Cursor and Copilot among them, all turning legitimate editor features into prompt-injection paths to code execution or data theft. 
The current fixes all point to the same lesson: the control that works sits in the platform, enforced in every mode and outside anything the model can be told to change. 
As more of the development workflow moves to agents that read the open web, a human in the loop only works as a control if the human is shown the step that matters, and the platform holds the line even after the model has been completely talked into crossing it. 
Article reasoning-pattern comparisonThis article: 6.1%Swati Khandelwal: 2.4%The Hacker News: 1.9%Confirmation Bias6.1%This article: 0.0%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias0.0%This article: 16.3%Swati Khandelwal: 3.5%The Hacker News: 3.3%Availability Heuristic16.3%This article: 2.9%Swati Khandelwal: 1.4%The Hacker News: 1.5%Representativeness Heuristic2.9%This article: 5.4%Swati Khandelwal: 0.7%The Hacker News: 0.6%Hindsight Bias5.4%This article: 0.0%Swati Khandelwal: 2.4%The Hacker News: 2.5%Overconfidence Bias0.0%This article: 4.1%Swati Khandelwal: 2.8%The Hacker News: 2.7%Framing Effect4.1%This article: 0.0%Swati Khandelwal: 0.9%The Hacker News: 1.0%Loss Aversion0.0%This article: 4.9%Swati Khandelwal: 0.7%The Hacker News: 0.6%Status Quo Bias4.9%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 7.8%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias7.8%This article: 10.4%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias10.4%This article: 27.1%Swati Khandelwal: 6.3%The Hacker News: 6.7%Negativity Bias27.1%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 4.5%Swati Khandelwal: 1.5%The Hacker News: 1.5%Recency Bias4.5%This article: 0.5%Swati Khandelwal: 0.2%The Hacker News: 0.3%Primacy Effect0.5%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 14.8%Swati Khandelwal: 3.9%The Hacker News: 4.0%Appeal to Authority14.8%This article: 8.0%Swati Khandelwal: 1.3%The Hacker News: 1.6%False Dilemma8.0%This article: 7.6%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope7.6%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 17.7%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization17.7%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 3.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon3.0%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question0.0%This article: 7.7%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)7.7%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 3.9%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof3.9%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division0.0%This article: 12.6%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal12.6%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 0.9%Swati Khandelwal: 2.5%The Hacker News: 2.3%Ambiguity (Equivocation)0.9%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 2.1%Swati Khandelwal: 1.0%The Hacker News: 1.4%Unattributed Quote2.1%This article: 1.7%Swati Khandelwal: 0.8%The Hacker News: 0.9%Quote-first Misdirection1.7%This article: 13.8%Swati Khandelwal: 2.7%The Hacker News: 2.3%Biased Writer Voice13.8%This article: 4.8%Swati Khandelwal: 5.0%The Hacker News: 4.4%Indoctrination4.8%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

1046 words analyzed.

Speakers

5speakers17%attributed speech865writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 14 words • 0.0% coverageWriter's voice • 37 words • 100.0% coverageIntezer • 25 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 23 words • 100.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 14 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 29 words • 100.0% coverageWriter's voice • 38 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageJohann Rehberger • 38 words • 0.0% coverageJohann Rehberger • 13 words • 0.0% coverageAWS • 16 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 4 words • 100.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageCymulate • 15 words • 0.0% coverageAWS • 19 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 18 words • 100.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 37 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageIntezer • 26 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageHacker News • 29 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 36 words • 100.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 50 words • 100.0% coverage
Selected voice

Johann Rehberger

75%flagged-word coverage
51 attributed words28% of attributed speech93% writer coverage
0%10.0%20.0%Biased Writer Voice-16.6 ptsWriter: 16.6%Johann Rehberger: 0.0%0.0%Indoctrination-5.8 ptsWriter: 5.8%Johann Rehberger: 0.0%0.0%Unattributed Quote-2.5 ptsWriter: 2.5%Johann Rehberger: 0.0%0.0%Quote-first Misdirection-2.1 ptsWriter: 2.1%Johann Rehberger: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.