Security researchers disclosed a vulnerability in AWS’s Kiro agentic IDE, assigned CVE-2026-10591 on July 22, 2026, that let a webpage containing hidden, near-invisible text hijack the AI coding assistant. When a developer asked Kiro to summarize an ordinary documentation page, the agent ingested the hidden instructions and used its file-write access to rewrite its own MCP server configuration, registering a malicious server whose startup command executed attacker-controlled code with the developer’s full privileges, without any approval prompt shown to the user. AWS patched the flaw in Kiro version 0.11.130; researchers stated no real Kiro users were found to have been exploited before the fix shipped.