Kiro IDE Vulnerability Lets Agents Leak Workspace Data
Kiro IDE versions below 0.8.135 have a security issue (CVE-2026-89332) where AI agents can modify workspace settings to exfiltrate sensitive data. A malicious repo could redirect the Powers registry URL to an external endpoint, sending your workspace info there—even before you approve the change. Update to version 0.8.135 or later immediately to stay safe.
source: [aws/security-bulletin]