← Back to feed
AI SecurityEmerging1 sourceAug 18, 2025 · 19:20via Embrace The Red (AI agent security)

Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection

Brief

The next three posts will cover high severity vulnerabilities in the Amazon Q Developer VS Code Extension (Amazon Q Developer), which is a very popular coding agent, with over 1 million downloads.

It is vulnerable to prompt injection from untrusted data and its security depends heavily on model behavior.

At a high level Amazon Q Developer can leak sensitive information from a developer’s machine, e. g. API keys, to external servers via DNS requests. An adversary can also exploit this behavior during an indirect

Read more on Embrace The Red (AI agent security)