Amazon Q extension bundles Node.js 24.9.0 which is flagged as vulnerable (fixed in 24.13.0)
- Dominant language
- TypeScript
- Stars
- 2k
- Forks
- 807
- Avg merge
- 10h 12m
- Merged PRs (30d)
- 7
Description
**Extension version:** Amazon Q 2.1.0
**VS Code version:** [your version]
**OS:** Windows
**Description:**
A vulnerability scanner has flagged the Node.js binary bundled with the Amazon Q
language server as vulnerable.
**Path:**
C:\Users\[username]\AppData\Local\aws\toolkits\language-servers\AmazonQ\1.66.0\servers\node.exe
- Installed version: 24.9.0.0
- Fixed version: 24.13.0
The extension reports as up to date (v2.1.0) but the bundled Node binary has not
been updated. This appears to be coming from the @aws/language-server-runtimes
dependency.
**Request:**
Please update the bundled Node.js runtime to 24.13.0 or later.
Contributor guide
Research direction
Inspect the @aws/language-server-runtimes dependency and the language-server packaging path first, then verify where the bundled Node.js binary version is selected. Update the runtime to 24.13.0 or later and confirm the installed Amazon Q extension no longer contains the vulnerable version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js, typescript
- Domain
- devtools, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 68/100