Affected Systems
Amazon Kiro IDE version 0.7.45 on Windows. Vulnerability affects both trusted and untrusted workspaces. Fixed in version 0.8.140 (current version is 1.0.337). No CVE assigned.
Exploitation Status
Proof-of-concept demonstrated by Mindguard. Exploitation difficulty assessed as low. No evidence of active exploitation in the wild. Requires user to open malicious workspace file and send any message to the agent.
Business Impact
Attackers can exfiltrate sensitive local workspace data without explicit user consent or malicious prompt submission. User only needs to open a crafted workspace file (File → Open Workspace From File) and send any message to trigger data transmission to external endpoints. Trust boundary failure allows repository-controlled content to influence the AI agent and modify security-relevant IDE configuration. Part of broader pattern of AI IDE vulnerabilities including previous Kiro flaw (CVE-2026-10591, CVSS 8.8) and similar issues in Cursor, Copilot CLI, Claude Code, and Gemini CLI.
Urgency
🟠Within 24 hours
Recommended Actions
- Upgrade Amazon Kiro IDE to version 0.8.140 or later immediately (current stable is 1.0.337)
- Audit developer workstations for Kiro IDE installations and enforce version compliance through endpoint management tools
- Educate development teams to avoid opening workspace files from untrusted sources; prefer opening folders directly rather than using File → Open Workspace From File
- Monitor network egress from developer workstations for unexpected connections to external endpoints, particularly from AI IDE processes
- Review and restrict Kiro Powers configurations and MCP server settings to limit agent capabilities in sensitive environments
