The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API call to the Q Developer CLI.



To mitigate this issue, users should upgrade to version v1.85.0. All installations of v1.84.0 should be removed from use.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-23144 The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API call to the Q Developer CLI. To mitigate this issue, users should upgrade to version v1.85.0. All installations of v1.84.0 should be removed from use.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Oct 2025 18:00:00 +0000


Wed, 30 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Jul 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Amazon
Amazon q Developer Vs Code Extension
Vendors & Products Amazon
Amazon q Developer Vs Code Extension

Wed, 30 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API call to the Q Developer CLI. To mitigate this issue, users should upgrade to version v1.85.0. All installations of v1.84.0 should be removed from use.
Title Inert Malicious script injected into Amazon Q Developer Visual Studio Code (VS Code) Extension
Weaknesses CWE-506
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2025-10-14T17:54:42.871Z

Reserved: 2025-07-25T21:50:50.324Z

Link: CVE-2025-8217

cve-icon Vulnrichment

Updated: 2025-07-30T13:23:18.772Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-30T01:15:25.863

Modified: 2025-10-14T18:15:37.360

Link: CVE-2025-8217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-30T11:10:20Z