Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
Summary
Researchers disclosed a high-severity flaw in Amazon Q Developer for VS Code that could let a malicious repository steal cloud credentials from a developer’s environment. The issue came from automatic execution of workspace configuration files without user permission. AWS released patches across the affected Amazon Q plugins and language server, and it said most customers will update automatically or only need to reload their IDE. Wiz also pointed out that similar risks can affect other AI coding tools, making this a broader developer-security concern.
Classifications
industries
Entertainment
applications
Anti Piracy
AI Classifications
Labels
SaaS
Shipping Software
Inventory Management Software
Linked Companies
Amazon.com, Inc.
$1B+
Wiz, Inc.
$50M to $100M