← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 19, 2025 · 21:20via Embrace The Red (AI agent security)

Amazon Q Developer: Remote Code Execution with Prompt Injection

Brief

The Amazon Q Developer VS Code Extension (Amazon Q) is a popular coding agent, with over 1 million downloads .

The extension is vulnerable to indirect prompt injection, and in this post we discuss a vulnerability that allowed an adversary (or also the AI for that matter) to run arbitrary commands on the host without the developer’s consent.

The resulting impact of the vulnerability is the same as CVE-2025-53773 that Microsoft fixed in GitHub Copilot, however AWS did not issue a CVE when patching the vulnerabili

Read more on Embrace The Red (AI agent security)