Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
27 August 2026
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers.
The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of