> Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection
[DATE: 18/08/2025 19:20]
[LANGUAGE: EN]
The next three posts will cover high severity vulnerabilities in the Amazon Q Developer VS Code Extension (Amazon Q Developer), which is a very popular coding agent, with over 1 million downloads.
It is vulnerable to prompt injection from untrusted data and its security depends heavily on model behavior.
At a high level Amazon Q Developer can leak sensitive information from a developer’s machine, e.g. API keys, to external servers via DNS requests.