# Amazon patches Kiro IDE prompt-injection data-exfiltration flaw

_Thursday, August 27, 2026 at 9:39 AM EDT · Security · Latest · Tier 2 — Notable_

![Amazon patches Kiro IDE prompt-injection data-exfiltration flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUdyQnHdjoEXFnc-5nB-6oglAbvpOYwuWqfjYkgeKH6HaqUjosKOHhmEQ_7StMkMBv53gz27Ilg-15yRaQ-hxoYi0ASuRMOCuPTHa8gP6a6PzYSewTWsDkKAx8dsMByZXDYDlRE1wRYoCvE7NuYqXdCpZ8_Y4E4tAUy0SBFl0S_XxLvpnjFRbqat0EwggW/s1700-e365/kiro-amazon.jpg)

Amazon implemented a fix in Kiro IDE version 0.8.140 for a prompt-injection flaw that could cause sensitive local information to be sent to an external endpoint, according to researchers cited by The Hacker News. The issue affected Kiro IDE 0.7.45 on Windows. Exploitation required a user to open a malicious project through a workspace file and then send a message to the agent. Researchers said the flow could work in both trusted and untrusted workspaces.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html)

---
Canonical: https://techandbusiness.org/newswire/lYPr217NflQJTQgvC9x92e
Retrieved: 2026-08-27T18:05:30.975Z
Publisher: Tech & Business (techandbusiness.org)
