AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
AWS fixed a Kiro prompt injection chain that rewrote mcp.json and launched attacker-controlled code with developer privileges, bypassing approval.
More info
