Amazon Kiro AI tool leaks your private data

Published August 27, 2026

Amazon's Kiro AI tool can accidentally share your private files or messages with attackers if they trick it with a special command. This happens because the tool does not properly check what you ask it to do.

Report priority
Medium

How it works

Attackers send a specially crafted command to Kiro that tricks it into revealing private files or messages you share with it.

What to do

Check if you're using Amazon Kiro version 0.7.45 or older on Windows by opening the app and looking for the version number in its settings or version screen.

Update Amazon Kiro to the latest version through the app's built-in update feature, then verify the new version number in the settings or version screen.

Technical details

You open Kiro and type a normal question about your code. An attacker sends a hidden command along with it that forces Kiro to send your private project files or chat history back to them instead of answering your question.

Amazon Kiro, an AI-powered IDE, suffers from a prompt injection vulnerability in version 0.7.45 for Windows. Attackers could manipulate Kiro's AI agents via carefully crafted prompts, forcing the tool to leak sensitive data through its Kiro Powers feature. This allows unauthorized access to private project files, configurations, or other confidential information stored within the IDE.

Researchers at Mindgard disclosed the flaw, which lacks a CVE identifier. No fixed version was mentioned in the report.