
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A critical vulnerability in Amazon Q, Amazon's AI-powered coding assistant for Visual Studio Code, allowed attackers to execute arbitrary code and steal cloud credentials by embedding malicious configuration files in code repositories. The flaw stemmed from Amazon Q's automatic execution of untrusted project configurations without user consent.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Amazon Q) that automatically executes commands from project configuration files, which is a use of AI to assist coding. The vulnerability allowed attackers to execute arbitrary code and access sensitive credentials, directly causing harm to property and security. The harm is realized, not just potential, as demonstrated by the proof-of-concept attack. Therefore, this qualifies as an AI Incident because the AI system's malfunction directly led to significant harm.[AI generated]