> Amazon Q Developer for VS Code Vulnerable to Invisible Prompt Injection
[DATE: 20/08/2025 11:00]
[LANGUAGE: EN]
The Amazon Q Developer VS Code Extension (Amazon Q) is a very popular coding agent, with over 1 million downloads.
In previous posts we showed how prompt injection vulnerabilities in Amazon Q could lead to:
Exfiltration of sensitive information from the user’s machine , and also to a System compromise by running arbitrary code Today we will show how an attack can leverage invisible Unicode Tag characters that humans cannot see.