Security
Amazon patches Kiro IDE prompt-injection data-exfiltration flaw
Image: Primary Amazon implemented a fix in Kiro IDE version 0.8.140 for a prompt-injection flaw that could cause sensitive local information to be sent to an external endpoint, according to researchers cited by The Hacker News. The issue affected Kiro IDE 0.7.45 on Windows. Exploitation required a user to open a malicious project through a workspace file and then send a message to the agent. Researchers said the flow could work in both trusted and untrusted workspaces.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire

