agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: final

Amazon Q Developer could be prompt-injected into RCE via the find command's -exec flag

2025-amazon-q-find-exec-rce · 2025-08-19

In the Amazon Q Developer VS Code extension (v1.81 and earlier), the `find` command was classified as read-only and so bypassed human confirmation. A prompt injection hidden in a source file could invoke `find -exec` to run arbitrary commands without approval; a proof of concept downloaded and ran a Sliver command-and-control agent. AWS patched it but assigned no CVE.

System

Framework
Amazon Q Developer (VS Code extension)
Tools
vscode, shell, amazon-q
Vendor
Amazon Web Services
Autonomy
human-in-the-loop

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → tool-misuse/over-broad-scope → unsafe-action/unauthorized-write
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

Instructions injected into a source file (including via invisible Unicode Tag characters) were followed by the agent when a developer asked it to analyze the file. Because `find` was categorised as read-only, it ran without the human-in-the-loop confirmation, and its `-exec` flag executed arbitrary commands — staged as a base64-encoded payload that was decoded and run.

Root cause

A command capable of executing arbitrary programs (`find ... -exec`) was misclassified as read-only, so it bypassed the approval gate. Combined with the agent acting on untrusted file content, this allowed injected instructions to reach command execution without user consent.

Contributing factors

  • The find command was classified as read-only despite its -exec flag running arbitrary commands.
  • The agent acted on instructions embedded in untrusted file content (including hidden Unicode).
  • Approval was enforced by a per-command classification that a single miscategorisation defeated.

Detection

Discovered and disclosed by researcher Johann Rehberger (wunderwuzzi); reported to AWS on 2025-07-04 and publicly disclosed on 2025-08-19.

Recovery

AWS reclassified `find` from read-only to a mutating command (restoring mandatory confirmation) and patched it in v1.85 (reported resolved by August 2025); AWS did not assign a CVE, stating it did not meet CNA criteria.

Prevention

Classify tool commands by their maximal capability, not their common use (a command that can execute programs is not read-only); default to requiring approval; strip or reject hidden/obfuscated instructions in analyzed content; treat file content as untrusted.

Blast radius

Data
Exploitation allowed arbitrary command execution on the developer's machine; a proof of concept downloaded and executed a Sliver command-and-control agent. internal
User harm
A disclosed vulnerability with a released fix; no confirmed in-the-wild exploitation was reported. none-reported
Scope
Amazon Q Developer VS Code users on v1.81 and earlier (1M+ installs)
Reversibility
reversible

References

CWE
CWE-77
OWASP LLM
LLM01 LLM06
MITRE ATLAS
AML.T0051 AML.T0053
Tags
prompt-injection rce amazon-q approval-bypass find-exec no-cve

Sources

Cite this incident

@misc{2025-amazon-q-find-exec-rce,
  title = {Amazon Q Developer could be prompt-injected into RCE via the find command's -exec flag},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-amazon-q-find-exec-rce/}
}