CVE-2025-8217Amazon Q Developer extension shipped with a wiper prompt
Amazon Q Developer for VS Code 1.84.0 shipped with an injected prompt meant to wipe data. AWS traced it to an over-scoped GitHub token in CodeBuild.
What happened
AWS security bulletin AWS-2025-015, dated 23 July 2025, reports that version 1.84.0 of the Amazon Q Developer extension for VS Code shipped with an injected wiper prompt. The prompt invoked q --trust-all-tools --no-interactive, which lets the agent use every tool without asking first.
AWS traced the root cause to a GitHub token in CodeBuild that had broader permissions than the build needed. The issue is tracked as CVE-2025-8217.
Why it worked
A build token with too much access made the release pipeline the attack surface. Once the prompt was inside the extension, the flags it used switched off confirmation, so nothing stood between the instruction and the tools.
What to do
- Scope CI and build tokens to the single repository and permission each job needs.
- Require review before anything lands in a release branch.
- Never run agents with --trust-all-tools or non-interactive flags on machines that hold real data.
- Keep tool approval switched on for destructive commands.
Use least-privilege credentialsRequire approval for consequential actionsVet skills, plugins and MCP servers
postmark-mcp: malicious MCP server copied every email
mcp-remote OS command injection via authorization_endpoint
Work through the security checklist →