vulnerability
Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
Critical
Summary
A high-severity vulnerability was discovered in the Amazon Q Developer extension for Visual Studio Code, allowing attackers to steal cloud credentials through malicious code repositories. The extension’s automatic execution of configuration files without user consent created an opportunity for attackers to gain access to sensitive information like API keys and session credentials. AWS has released a patch, but the issue highlights a broader risk in AI-powered coding tools.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data