SECURITY·중요도 8·2026. 08. 27.·The Hacker News

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

── KO ──────────────────

아마존 Kiro의 보안 취약점이 데이터 유출을 초래할 수 있음.

사이버 보안 연구자들이 아마존 Kiro에서 발견된 취약점에 대한 세부 정보를 공개했습니다. 이 취약점은 프롬프트 인젝션을 통해 민감한 데이터가 유출될 수 있는 가능성을 나타냅니다. Kiro IDE 0.7.45에서 작동하며, 현재까지 CVE 식별자는 없습니다.


── EN ──────────────────

Amazon Kiro vulnerability can lead to data exfiltration via prompt injection.

Cybersecurity researchers have disclosed a vulnerability in Amazon Kiro that can facilitate data exfiltration through prompt injection. The security flaw affects Kiro IDE version 0.7.45 on Windows and currently does not have a CVE identifier. This highlights significant risks associated with the integrated development environment.

원문 보기 →목록으로