Overview

Story hub for the July 2026 disclosure (Intezer + kodem-security) of remote code execution in kiro via invisible web-text prompt-injection rewriting ~/.kiro/settings/mcp.json.

Recent Developments

  • Affected: Kiro 0.9.2 (macOS), 0.10.16 (Ubuntu); patched 0.11.130; current line 1.0.x
  • AWS assigned no CVE — scanner blind-spot angle
  • Third mcp.json trust-boundary class against Kiro since 2025
  • Platform fix: protected paths requiring explicit approval for mcp.json / sensitive files

Warning

Do not publish exploit payloads or reproduction steps in articles — defensive guidance only (upgrade + inspect mcp.json).

Sources