216.73.216.226

CVE-2025-8217

· Published 30/07/2025 01:15 · Modified 31/07/2025 18:42

Labels: CVE-2025-8217 2025-07-30CVE-2025-8217CWE-506ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
30/07/2025 01:15
Modified
31/07/2025 18:42
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API call to the Q Developer CLI. To mitigate this issue, users should upgrade to version v1.85.0. All installations of v1.84.0 should be removed from use.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

Affected products (CPE)

ProductCPE
amazon / q developer cpe:2.3:a:amazon:q_developer:1.84.0:*:*:*:*:*:*:*
amazon / q developer cpe:2.3:a:amazon:q_developer:1.85.0:*:*:*:*:*:*:*

References