跳到正文
原文
Johann Rehberger / Embrace The Red(RSS)·· 2025-08-20精选AI 评分79

Amazon Q Developer VS Code 扩展存在提示词注入导致远程代码执行漏洞

Amazon Q Developer: Remote Code Execution with Prompt Injection

AI 导读

安全研究者 Johann Rehberger 披露 Amazon Q Developer VS Code 扩展(下载量超 100 万)存在间接提示词注入漏洞:executeBash 将 find 归类为 readonly 并跳过人工确认。

推荐理由

作者亲测复现了 Amazon Q Developer 的间接提示词注入到任意命令执行路径,读者可借此理解 Agent 权限模型的风险。

来源:Johann Rehberger / Embrace The Red(RSS) · embracethered.com