Amazon Q Developer could be prompt-injected into RCE via the find command's -exec flag
2025-amazon-q-find-exec-rce · 2025-08-19
In the Amazon Q Developer VS Code extension (v1.81 and earlier), the `find` command was classified as read-only and so bypassed human confirmation. A prompt injection hidden in a source file could invoke `find -exec` to run arbitrary commands without approval; a proof of concept downloaded and ran a Sliver command-and-control agent. AWS patched it but assigned no CVE.
System
- Framework
- Amazon Q Developer (VS Code extension)
- Tools
- vscode, shell, amazon-q
- Vendor
- Amazon Web Services
- Autonomy
- human-in-the-loop
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → tool-misuse/over-broad-scope → unsafe-action/unauthorized-write
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
Instructions injected into a source file (including via invisible Unicode Tag characters) were followed by the agent when a developer asked it to analyze the file. Because `find` was categorised as read-only, it ran without the human-in-the-loop confirmation, and its `-exec` flag executed arbitrary commands — staged as a base64-encoded payload that was decoded and run.
Root cause
A command capable of executing arbitrary programs (`find ... -exec`) was misclassified as read-only, so it bypassed the approval gate. Combined with the agent acting on untrusted file content, this allowed injected instructions to reach command execution without user consent.
Contributing factors
- The find command was classified as read-only despite its -exec flag running arbitrary commands.
- The agent acted on instructions embedded in untrusted file content (including hidden Unicode).
- Approval was enforced by a per-command classification that a single miscategorisation defeated.
Detection
Discovered and disclosed by researcher Johann Rehberger (wunderwuzzi); reported to AWS on 2025-07-04 and publicly disclosed on 2025-08-19.
Recovery
AWS reclassified `find` from read-only to a mutating command (restoring mandatory confirmation) and patched it in v1.85 (reported resolved by August 2025); AWS did not assign a CVE, stating it did not meet CNA criteria.
Prevention
Classify tool commands by their maximal capability, not their common use (a command that can execute programs is not read-only); default to requiring approval; strip or reject hidden/obfuscated instructions in analyzed content; treat file content as untrusted.
Blast radius
- Data
- Exploitation allowed arbitrary command execution on the developer's machine; a proof of concept downloaded and executed a Sliver command-and-control agent. internal
- User harm
- A disclosed vulnerability with a released fix; no confirmed in-the-wild exploitation was reported. none-reported
- Scope
- Amazon Q Developer VS Code users on v1.81 and earlier (1M+ installs)
- Reversibility
- reversible
References
- CWE
- CWE-77
- OWASP LLM
- LLM01 LLM06
- OWASP Agentic
- T2 T3
- MITRE ATLAS
- AML.T0051 AML.T0053
- Related
- 2025-amazon-q-wiper-supply-chain 2025-github-copilot-autoapprove-rce 2025-claude-code-dns-exfiltration
- Tags
- prompt-injection rce amazon-q approval-bypass find-exec no-cve
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-amazon-q-find-exec-rce/
@misc{2025-amazon-q-find-exec-rce,
title = {Amazon Q Developer could be prompt-injected into RCE via the find command's -exec flag},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-amazon-q-find-exec-rce/}
}