aws / aws/aws-toolkit-vscode

Amazon Q extension bundles Node.js 24.9.0 which is flagged as vulnerable (fixed in 24.13.0)

Open
#8,781 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
2k
Forks
807
Avg merge
10h 12m
Merged PRs (30d)
7

Description

**Extension version:** Amazon Q 2.1.0
**VS Code version:** [your version]
**OS:** Windows

**Description:**
A vulnerability scanner has flagged the Node.js binary bundled with the Amazon Q
language server as vulnerable.

**Path:**
C:\Users\[username]\AppData\Local\aws\toolkits\language-servers\AmazonQ\1.66.0\servers\node.exe

- Installed version: 24.9.0.0
- Fixed version: 24.13.0

The extension reports as up to date (v2.1.0) but the bundled Node binary has not
been updated. This appears to be coming from the @aws/language-server-runtimes
dependency.

**Request:**
Please update the bundled Node.js runtime to 24.13.0 or later.

Contributor guide

Open the contributing guide

Research direction

Inspect the @aws/language-server-runtimes dependency and the language-server packaging path first, then verify where the bundled Node.js binary version is selected. Update the runtime to 24.13.0 or later and confirm the installed Amazon Q extension no longer contains the vulnerable version.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js, typescript
Domain
devtools, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.