Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-09-24

HighVendor post

Amazon Kiro Prompt Injection Let Untrusted Repositories Modify Auto-Loaded Global Configuration

Analysis of CVE-2026-95985, an Amazon Kiro flaw that let crafted repositories drive agent writes to auto-loaded global configuration.

Amazon Kiro IDEGovernance bypassRepository-borne prompt injection causing writes outside the trusted workspaceDeveloper workstations running Amazon Kiro IDE before version 1.0.242

What happened

In a crafted repository opened as an untrusted workspace, an ordinary user message can cause the Kiro agent to write attacker-directed changes into auto-loaded global configuration paths.

Why it matters

Unauthorized global configuration changes and potential arbitrary command execution with the developer's local privileges; no real-world exploitation was reported in the advisory.

Missing authorization check

Independent authorization for agent-originated writes outside the repository, especially writes to global agent configuration and executable tool definitions.

Would PP block it?

The prompt injection can still enter the model context, but the resolved destination, content, and requesting agent can be evaluated outside Kiro. A write to the global configuration directory without matching authority would fail closed.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-09-24

    AWS publishes security bulletin 2026-117-AWS and assigns CVE-2026-95985.

  2. 2026-09-24

    Kiro IDE 1.0.242 is identified as the fixed release.

Technical breakdown

  • A remote actor prepares a repository containing crafted instructions that Kiro can load into agent context.
  • The user opens the repository as an untrusted workspace and sends any message to the agent.
  • The file-write tool can act on the injected instructions and target auto-loaded paths outside the repository in Kiro's global configuration directory.
  • AWS rates the issue High and advises users of older versions to inspect the global configuration directory for entries they did not create.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Runtime Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Filesystem boundary before writes to the global Kiro configuration directory
Still needs
Permission Protocol does not remove the prompt injection, repair Kiro's file-write implementation, or prevent effects that occur entirely inside the compromised agent context.
Receipt required for
Writing global Kiro configuration or registering executable tools from an untrusted workspace

A Runtime Gate can require a separately authenticated receipt before a Kiro-originated write crosses from an untrusted workspace into global configuration.

Start small

Put the relevant gate at this action boundary.

This incident maps to Runtime Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop