AWS patches Kiro flaw that let web pages trigger silent code execution

Intezer and Kodem Security said hidden instructions in fetched HTML could rewrite Kiro’s MCP settings and run attacker code; the fix landed in v0.11.130 without a CVE.

Summary

verifying reliability

Terms & Concepts

No specialized terms available for this topic.