Amazon Q Developer and Kiro – Prompt Injection Issues in Kiro and Q IDE plugins
Bulletin ID: AWS-2025-019 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/10/07 01:30 PM PDT Description: We are aware of blog posts by Embrace The Red (“The Month of AI Bugs”) describing prompt injection issues in Amazon Q Developer and Kiro. Amazon Q Developer: Remote Code Execution with Prompt Injection” and “Amazon Q Developer for VS Code Vulnerable to Invisible Prompt Injection. These issues require an open chat session and intentional access to a malicious file using commands such as find, grep, or echo, which could be executed without Human-in-the-Loop (HITL) confirmation. In some cases, invisible control characters could obfuscate these commands. On July 17, 2025, we released Language Server v1.22.0, which requires HITL confirmation for these commands Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection. This issue requires a developer to accept a prompt-injected suggestion including commands such as ping or dig, which could exfiltrate metadata via DNS queries without HITL confirmation. On July 29, 2025, we released Language Server v1.24.0, which requires HITL confirmation for these commands. AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection. This issue requires local system access to inject instructions that lead to arbitrary code execution via Kiro IDE or MCP settings files without HITL confirmation in either Kiro's Autopilot or Supervised mode. On August 1, 2025, we released Kiro version 0.1.42, which requires HITL confirmation for these actions when configured in Supervised mode. Amazon Q Developer and Kiro are built on the principles of agentic development, enabling developers to work more efficiently with the help of AI agents. As customers adopt AI-enhanced development workflows, we recommend they evaluate and implement appropriate security controls and policies based on their specific environments and shared responsibility models (AWS, Amazon Q, Kiro). Amazon Q Developer and Kiro provide safeguards, including Human-in-the-Loop protections and customizable execution policies, to support secure adoption. Affected versions: Amazon Q Developer for find, grep, echo (version <1.22.0) Amazon Q Developer for ping, dig: (versions <1.24.0) AWS Kiro: version 0.1.42
AI Analysis
Technical Summary
The vulnerabilities involve prompt injection attacks in Amazon Q Developer and AWS Kiro IDE plugins that allow execution of commands like find, grep, echo, ping, and dig without HITL confirmation, potentially leading to remote code execution and secret exfiltration via DNS queries. Invisible control characters can obfuscate malicious commands. AWS addressed these issues by releasing Language Server v1.22.0 and v1.24.0, and Kiro version 0.1.42, which require HITL confirmation for these commands and actions, especially in supervised modes. Exploitation requires an open chat session and either local system access or developer acceptance of prompt-injected suggestions. These products implement agentic AI development workflows and provide customizable execution policies to mitigate risks.
Potential Impact
If unpatched, attackers with local access or the ability to provide malicious files or prompt injections could execute arbitrary code remotely or locally and exfiltrate secrets via DNS queries without developer confirmation. This could compromise development environments and leak sensitive metadata. However, exploitation requires specific conditions such as an open chat session, intentional developer interaction, or local system access. The vulnerabilities are rated critical due to the potential for code execution and data leakage.
Mitigation Recommendations
AWS has released patches that require Human-in-the-Loop (HITL) confirmation for the affected commands and actions: Language Server v1.22.0 (for find, grep, echo), Language Server v1.24.0 (for ping, dig), and Kiro version 0.1.42 (for arbitrary code execution in supervised mode). Users should upgrade to these versions or later and restart the plugins or applications to enforce HITL protections. After upgrading, these commands and actions cannot be executed without explicit developer confirmation, mitigating the risk. No further immediate action is required beyond applying these updates and configuring supervised mode where applicable.
Amazon Q Developer and Kiro – Prompt Injection Issues in Kiro and Q IDE plugins
Description
Bulletin ID: AWS-2025-019 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/10/07 01:30 PM PDT Description: We are aware of blog posts by Embrace The Red (“The Month of AI Bugs”) describing prompt injection issues in Amazon Q Developer and Kiro. Amazon Q Developer: Remote Code Execution with Prompt Injection” and “Amazon Q Developer for VS Code Vulnerable to Invisible Prompt Injection. These issues require an open chat session and intentional access to a malicious file using commands such as find, grep, or echo, which could be executed without Human-in-the-Loop (HITL) confirmation. In some cases, invisible control characters could obfuscate these commands. On July 17, 2025, we released Language Server v1.22.0, which requires HITL confirmation for these commands Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection. This issue requires a developer to accept a prompt-injected suggestion including commands such as ping or dig, which could exfiltrate metadata via DNS queries without HITL confirmation. On July 29, 2025, we released Language Server v1.24.0, which requires HITL confirmation for these commands. AWS Kiro: Arbitrary Code Execution via Indirect Prompt Injection. This issue requires local system access to inject instructions that lead to arbitrary code execution via Kiro IDE or MCP settings files without HITL confirmation in either Kiro's Autopilot or Supervised mode. On August 1, 2025, we released Kiro version 0.1.42, which requires HITL confirmation for these actions when configured in Supervised mode. Amazon Q Developer and Kiro are built on the principles of agentic development, enabling developers to work more efficiently with the help of AI agents. As customers adopt AI-enhanced development workflows, we recommend they evaluate and implement appropriate security controls and policies based on their specific environments and shared responsibility models (AWS, Amazon Q, Kiro). Amazon Q Developer and Kiro provide safeguards, including Human-in-the-Loop protections and customizable execution policies, to support secure adoption. Affected versions: Amazon Q Developer for find, grep, echo (version <1.22.0) Amazon Q Developer for ping, dig: (versions <1.24.0) AWS Kiro: version 0.1.42
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerabilities involve prompt injection attacks in Amazon Q Developer and AWS Kiro IDE plugins that allow execution of commands like find, grep, echo, ping, and dig without HITL confirmation, potentially leading to remote code execution and secret exfiltration via DNS queries. Invisible control characters can obfuscate malicious commands. AWS addressed these issues by releasing Language Server v1.22.0 and v1.24.0, and Kiro version 0.1.42, which require HITL confirmation for these commands and actions, especially in supervised modes. Exploitation requires an open chat session and either local system access or developer acceptance of prompt-injected suggestions. These products implement agentic AI development workflows and provide customizable execution policies to mitigate risks.
Potential Impact
If unpatched, attackers with local access or the ability to provide malicious files or prompt injections could execute arbitrary code remotely or locally and exfiltrate secrets via DNS queries without developer confirmation. This could compromise development environments and leak sensitive metadata. However, exploitation requires specific conditions such as an open chat session, intentional developer interaction, or local system access. The vulnerabilities are rated critical due to the potential for code execution and data leakage.
Mitigation Recommendations
AWS has released patches that require Human-in-the-Loop (HITL) confirmation for the affected commands and actions: Language Server v1.22.0 (for find, grep, echo), Language Server v1.24.0 (for ping, dig), and Kiro version 0.1.42 (for arbitrary code execution in supervised mode). Users should upgrade to these versions or later and restart the plugins or applications to enforce HITL protections. After upgrading, these commands and actions cannot be executed without explicit developer confirmation, mitigating the risk. No further immediate action is required beyond applying these updates and configuring supervised mode where applicable.
Technical Details
- Article Source
- {"url":"https://aws.amazon.com/security/security-bulletins/rss/aws-2025-019/","fetched":true,"fetchedAt":"2026-05-26T20:30:23.323Z","wordCount":426}
Threat ID: 6a1602eae29bf47b505d9f89
Added to database: 05/26/2026, 20:30:34 UTC
Last enriched: 06/05/2026, 19:31:07 UTC
Last updated: 07/31/2026, 15:06:57 UTC
Views: 159
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.