Overview
Story hub for the July 2026 disclosure (Intezer + kodem-security) of remote code execution in kiro via invisible web-text prompt-injection rewriting ~/.kiro/settings/mcp.json.
Recent Developments
- Affected: Kiro 0.9.2 (macOS), 0.10.16 (Ubuntu); patched 0.11.130; current line 1.0.x
- AWS assigned no CVE — scanner blind-spot angle
- Third mcp.json trust-boundary class against Kiro since 2025
- Platform fix: protected paths requiring explicit approval for mcp.json / sensitive files
Warning
Do not publish exploit payloads or reproduction steps in articles — defensive guidance only (upgrade + inspect mcp.json).
Related
- kiro
- amazon
- mcp
- prompt-injection
- agentic-ide
- ai-agent-security
- intezer
- kodem-security
- model-context-protocol