CVE-2025-8217 Details
Description
The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API call to the Q Developer CLI. To mitigate this issue, users should upgrade to version v1.85.0. All installations of v1.84.0 should be removed from use.
A vulnerability exists in the Amazon Q Developer Visual Studio Code extension, version 1.84.0, due to the injection of malicious code that attempts to call the Q Developer CLI. This code is executed when the extension is launched, but a syntax error prevents it from successfully making an API call. The issue arose from an improperly scoped GitHub token that allowed a threat actor to inject the malicious code, which was then included in the extension's release. Although the injected code could not execute or impact services or customer environments, it remains in place in current installations of version 1.84.0.
Users should update to version 1.85.0 of the Amazon Q Developer Visual Studio Code extension. Version 1.84.0 has been removed from distribution channels, but existing installations should be uninstalled. To update the extension, open Visual Studio Code, navigate to the Extensions panel, locate Amazon Q Developer, and click the Update button.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2025CISA-ADP
Assessed Jul 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/AWS-2025-015/ | AMZN | AdvisoryRemedyVendor |
| https://github.com/aws/aws-toolkit-vscode/releases/tag/amazonq%2Fv1.85.0 | AMZN | |
| https://github.com/aws/aws-toolkit-vscode/security/advisories/GHSA-7g7f-ff96-5gcw | AMZN | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-506 | Embedded Malicious Code | AMZN |
Affected Products
| Product | Versions |
|---|---|
| Amazon Q Developer | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | CVE Modified | AMZN |
| Jul 30, 2025 | New CVE Received | AMZN |
Volerion