Amazon quietly fixed Q Developer flaws that made AI agent vulnerable to prompt injection, RCE

Move along, nothing to see here

Amazon has quietly fixed a couple of security issues in its coding agent: Amazon Q Developer VS Code extension. Attackers could use these vulns to leak secrets, including API keys from a developer’s machine, and run arbitrary code.…

This article has been indexed from The Register – Security

Read the original article: