r/linuxadmin • u/Expert_Sort7434 • 1h ago
AWS Kiro MCP prompt injection → unapproved RCE (no CVE, joint Intezer/Kodem research)
Based on the technical breakdown Intezer and Kodem Security published July 19, here's the architectural impact for anyone running Kiro or evaluating agentic IDEs.
Root cause: ~/.kiro/settings/mcp.json wasn't in Kiro's protected-paths list. The agent's fsWrite tool could modify it without a real approval gate, and the file auto-reloads on change, starting whatever MCP server it describes.
Attack: hidden color:#fff;font-size:1px text on a normal-looking doc page instructs Kiro to add an MCP server whose launch command is an inline Node.js exfil script. Developer only approved fetching the URL. Everything downstream — file write, server creation, code exec — happened silently.
Fixed in 0.11.130. No CVE issued. Worth noting this is the second time this exact file-write primitive has surfaced in Kiro since its 2025 launch — the first fix only covered Supervised mode, leaving default Autopilot exposed, which is what got hit this time.
Full writeup w/ attack-chain diagram and remediation list: [background link, footnote]
Anyone running agentic IDEs in Autopilot-equivalent modes in production — what's your actual control for file writes to tool/MCP config paths? Approval dialogs clearly aren't sufficient on their own.
https://www.techgines.com/post/aws-kiro-mcp-prompt-injection-vulnerability