# Amazon patches Kiro IDE prompt-injection data-exfiltration flaw

_Published Thursday, August 27, 2026 at 12:07 PM EDT · Security · Latest · Tier 2 — Notable_

![Amazon patches Kiro IDE prompt-injection data-exfiltration flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUdyQnHdjoEXFnc-5nB-6oglAbvpOYwuWqfjYkgeKH6HaqUjosKOHhmEQ_7StMkMBv53gz27Ilg-15yRaQ-hxoYi0ASuRMOCuPTHa8gP6a6PzYSewTWsDkKAx8dsMByZXDYDlRE1wRYoCvE7NuYqXdCpZ8_Y4E4tAUy0SBFl0S_XxLvpnjFRbqat0EwggW/s1700-e365/kiro-amazon.jpg)

Amazon implemented a fix in Kiro IDE version 0.8.140 for a prompt-injection flaw that could cause sensitive local information to be sent to an external endpoint, according to researchers cited by The Hacker News. The issue affected Kiro IDE 0.7.45 on Windows. Exploitation required a user to open a malicious project through a workspace file and then send a message to the agent. Researchers said the flow could work in both trusted and untrusted workspaces.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html)

---
Canonical: https://techandbusiness.org/newswire/lYPr217NflQJTQgvC9x92e
Published: 2026-08-27T16:07:12.696Z
Story chronology: 2026-08-27T13:39:56.000Z
Retrieved: 2026-10-11T21:48:48.399Z
Publisher: Tech & Business (techandbusiness.org)
