CVE-2026-12957
CVSS 7.8 HIGH: improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. EPSS 0.2% (7th percentile).
Vulnerabilities · 77 days ago
A cloned repository was enough to cross the trust boundary here. Amazon Q Developer read MCP settings from the workspace and launched local helper processes before the code was reviewed, so opening a repo could turn into command execution in the developer’s own cloud session, not just a config change inside the IDE.
Wiz says those helpers inherited the full environment on the machine. That exposed AWS credentials, CLI tokens, API secrets, and SSH sockets already present on the workstation. Amazon patched CVE-2026-12957 in Language Servers for AWS 1.65.0, and AWS points customers to 1.69.0 because that build also fixes CVE-2026-12958.
The risk reaches beyond this one extension. Any IDE assistant that auto-loads workspace configs or spawns local tools can turn a trusted repo open into credential theft before the first line of code is reviewed.
CVSS 7.8 HIGH: improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. EPSS 0.2% (7th percentile).
4 sources covering this story
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
Adversaries could plant a malicious repository that executes arbitrary code and steals cloud credentials, showcasing MCP risk.
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
Amazon patched CVE-2026-12957, a high-severity Amazon Q Developer flaw that let malicious MCP config run commands and steal AWS credentials.
Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
AWS has patched the vulnerability and published its own advisory to inform customers about the potential impact.
Amazon Q Vulnerability: Compromise via MCP Auto-Execution | Wiz Blog
Wiz Research found a critical Amazon Q vulnerability that enabled code execution and cloud credential theft through malicious MCP configurations.
Part of the PlainSec briefing for 2026-06-30