The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API call to the Q Developer CLI. To mitigate this issue, users should upgrade to version v1.85.0. All installations of v1.84.0 should be removed from use.
History

Wed, 30 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Jul 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Amazon
Amazon q Developer Vs Code Extension
Vendors & Products Amazon
Amazon q Developer Vs Code Extension

Wed, 30 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API call to the Q Developer CLI. To mitigate this issue, users should upgrade to version v1.85.0. All installations of v1.84.0 should be removed from use.
Title Inert Malicious script injected into Amazon Q Developer Visual Studio Code (VS Code) Extension
Weaknesses CWE-506
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published: 2025-07-30T00:34:06.733Z

Updated: 2025-07-30T15:25:16.138Z

Reserved: 2025-07-25T21:50:50.324Z

Link: CVE-2025-8217

cve-icon Vulnrichment

Updated: 2025-07-30T13:23:18.772Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-30T01:15:25.863

Modified: 2025-07-31T18:42:37.870

Link: CVE-2025-8217

cve-icon Redhat

No data.