Amazon Q Developer for VS Code Vulnerable to Invisible Prompt Injection
The Amazon Q Developer VS Code Extension (Amazon Q) is a very popular coding agent, with over 1 million downloads.
In previous posts we showed how prompt injection vulnerabilities in Amazon Q could lead to:
- Exfiltration of sensitive information from the user’s machine , and also to a
- System compromise by running arbitrary code
Today we will show how an attack can leverage invisible Unicode Tag characters that humans cannot see. However, the AI will interpret them as instructions, and this can be used to invoke tools and other nefarious actions.