← All stories
● Covered by 1 source · 1 reportMedium impact

Amazon Q Developer Flaw Allows Code Execution via Malicious Repos

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Flaw allowed running arbitrary code in developers' cloud sessions
  • Tracked as CVE-2026-12957 with CVSS score of 8.5
  • Patched in Language Servers for AWS version 1.65.0
  • Minimum plugin versions updated for popular IDEs

Overview of the Vulnerability

Amazon Q Developer had a significant flaw allowing attackers to leverage malicious repositories. By opening a repository and trusting the workspace, a developer could inadvertently execute code as the system's active user.

Mechanism of the Attack

The vulnerability involved the reading of a specific MCP configuration file, .amazonq/mcp.json. Once loaded, Amazon Q would initiate defined MCP servers that could access sensitive credentials, enabling the execution of malicious commands on the developer's cloud session without further authentication.

Consequences of Exploitation

Wiz Research demonstrated the exploit by making the malicious file execute a command to retrieve AWS session information. Depending on cloud permissions, this could allow an attacker to alter infrastructure or service access, posing serious security risks.

Response and Mitigation

Amazon has addressed the vulnerability with a patch that requires developers to confirm untrusted MCP servers before executing commands. Users are urged to upgrade to Language Servers for AWS version 1.69.0 to ensure they are protected against this flaw and a related issue.

Recommended Actions for Users

Developers using Amazon Q should update to the patched versions of Language Servers for AWS and relevant IDE plugins as soon as possible. The update addresses CVE-2026-12957 and also resolves an additional vulnerability identified as CVE-2026-12958.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A high-severity flaw in Amazon Q Developer permitted malicious repositories to execute code and steal developer credentials. The issue stemmed from the way Amazon's AI coding assistant handled Model Context Protocol servers, which has now been patched by Amazon.