Skip to content

Amazon Q extension bundles Node.js 24.9.0 which is flagged as vulnerable (fixed in 24.13.0) #8781

@sgf-HonestAnt

Description

@sgf-HonestAnt

Extension version: Amazon Q 2.1.0
VS Code version: [your version]
OS: Windows

Description:
A vulnerability scanner has flagged the Node.js binary bundled with the Amazon Q
language server as vulnerable.

Path:
C:\Users[username]\AppData\Local\aws\toolkits\language-servers\AmazonQ\1.66.0\servers\node.exe

  • Installed version: 24.9.0.0
  • Fixed version: 24.13.0

The extension reports as up to date (v2.1.0) but the bundled Node binary has not
been updated. This appears to be coming from the @aws/language-server-runtimes
dependency.

Request:
Please update the bundled Node.js runtime to 24.13.0 or later.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions