跳到正文
原文
Johann Rehberger / Embrace The Red(RSS)·· 2025-08-19精选AI 评分77

Amazon Q Developer 提示词注入可经 DNS 请求泄露开发者密钥

Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection

AI 导读

安全研究人员 Johann Rehberger 披露 Amazon Q Developer VS Code 扩展(下载量超 100 万)存在高危漏洞:处理不可信数据时可被提示词注入劫持,通过 ping 等 readOnly 命令将开发者 .env 文件内容经 DNS 请求外泄。

推荐理由

作者第一手复现了 Amazon Q Developer 通过 DNS 请求泄露 .env 密钥的提示词注入漏洞,并披露 AWS 已静默修复但未发公告或 CVE。

来源:Johann Rehberger / Embrace The Red(RSS) · embracethered.com