Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Amazon Q Developer and Kiro – Prompt Injection Issues in Kiro and Q IDE plugins

0
Critical
Vulnerabilityremotelocal
Published: 06/05/2026 (06/05/2026, 19:19:25 UTC)
Source: AWS Security Bulletins

Description

Bulletin ID: AWS-2025-019 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/10/07 01:30 PM PDT Description: We are aware of blog posts by Embrace The Red (“The Month of AI Bugs”) describing prompt injection issues in Amazon Q Developer and Kiro. Amazon Q Developer: Remote Code Execution with Prompt Injection” and “Amazon Q Developer for VS Code Vulnerable to Invisible Prompt Injection. These issues require an open chat session and intentional access to a malicious file using commands such as find, grep, or echo, which could be executed without Human-in-the-Loop (HITL) confirmation. In some cases, invisible control characters could obfuscate these commands. On July 17, 2025, we released Language Server v1.22.0, which requires HITL confirmation for these commands Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection. This issue requires a developer to accept a prompt-injected suggestion including commands such as ping or dig, which could exfiltrate metadata via DNS queries without HITL confirmation. On July 29, 2025, we released Language Server v1.24.0, which requires HITL confirmation for these commands. AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection. This issue requires local system access to inject instructions that lead to arbitrary code execution via Kiro IDE or MCP settings files without HITL confirmation in either Kiro's Autopilot or Supervised mode. On August 1, 2025, we released Kiro version 0.1.42, which requires HITL confirmation for these actions when configured in Supervised mode. Amazon Q Developer and Kiro are built on the principles of agentic development, enabling developers to work more efficiently with the help of AI agents. As customers adopt AI-enhanced development workflows, we recommend they evaluate and implement appropriate security controls and policies based on their specific environments and shared responsibility models (AWS, Amazon Q, Kiro). Amazon Q Developer and Kiro provide safeguards, including Human-in-the-Loop protections and customizable execution policies, to support secure adoption. Affected versions: Amazon Q Developer for find, grep, echo (version <1.22.0) Amazon Q Developer for ping, dig: (versions <1.24.0) AWS Kiro: version 0.1.42

Affected software

Affected versions
<1.22.0<1.24.0=0.1.42

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/05/2026, 19:31:07 UTC

Technical Analysis

The vulnerabilities involve prompt injection attacks in Amazon Q Developer and AWS Kiro IDE plugins that allow execution of commands like find, grep, echo, ping, and dig without HITL confirmation, potentially leading to remote code execution and secret exfiltration via DNS queries. Invisible control characters can obfuscate malicious commands. AWS addressed these issues by releasing Language Server v1.22.0 and v1.24.0, and Kiro version 0.1.42, which require HITL confirmation for these commands and actions, especially in supervised modes. Exploitation requires an open chat session and either local system access or developer acceptance of prompt-injected suggestions. These products implement agentic AI development workflows and provide customizable execution policies to mitigate risks.

Potential Impact

If unpatched, attackers with local access or the ability to provide malicious files or prompt injections could execute arbitrary code remotely or locally and exfiltrate secrets via DNS queries without developer confirmation. This could compromise development environments and leak sensitive metadata. However, exploitation requires specific conditions such as an open chat session, intentional developer interaction, or local system access. The vulnerabilities are rated critical due to the potential for code execution and data leakage.

Mitigation Recommendations

AWS has released patches that require Human-in-the-Loop (HITL) confirmation for the affected commands and actions: Language Server v1.22.0 (for find, grep, echo), Language Server v1.24.0 (for ping, dig), and Kiro version 0.1.42 (for arbitrary code execution in supervised mode). Users should upgrade to these versions or later and restart the plugins or applications to enforce HITL protections. After upgrading, these commands and actions cannot be executed without explicit developer confirmation, mitigating the risk. No further immediate action is required beyond applying these updates and configuring supervised mode where applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://aws.amazon.com/security/security-bulletins/rss/aws-2025-019/","fetched":true,"fetchedAt":"2026-05-26T20:30:23.323Z","wordCount":426}

Threat ID: 6a1602eae29bf47b505d9f89

Added to database: 05/26/2026, 20:30:34 UTC

Last enriched: 06/05/2026, 19:31:07 UTC

Last updated: 07/31/2026, 15:06:57 UTC

Views: 159

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses