CVE-2026-12957
CVSS 7.8 HIGH: improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. EPSS 0.2% (7th percentile).
Vulnerabilities & Exploits · Supply Chain
A cloned repository was enough to cross the trust boundary here. Amazon Q Developer read MCP settings from the workspace and launched local helper processes before the code was reviewed, so opening a repo could turn into command execution in the developer’s own cloud session, not just a config change inside the IDE.
Wiz says those helpers inherited the full environment on the machine. That exposed AWS credentials, CLI tokens, API secrets, and SSH sockets already present on the workstation. Amazon patched CVE-2026-12957 in Language Servers for AWS 1.65.0, and AWS points customers to 1.69.0 because that build also fixes CVE-2026-12958.
The risk reaches beyond this one extension. Any IDE assistant that auto-loads workspace configs or spawns local tools can turn a trusted repo open into credential theft before the first line of code is reviewed.
4 sources · Jun 29
CVSS 7.8 HIGH: improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. EPSS 0.2% (7th percentile).
Dark Reading
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
Adversaries could plant a malicious repository that executes arbitrary code and steals cloud credentials, showcasing MCP risk.
originalThe Hacker News
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
Amazon patched CVE-2026-12957, a high-severity Amazon Q Developer flaw that let malicious MCP config run commands and steal AWS credentials.
originalSecurityWeek
Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact.
originalPart of the PlainSec briefing for 2026-06-26
Every edition of this story: Repo Opens Became Live Cloud Compromise