logo

Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments

ID: 8723cf6a-2b62-536e-a958-17ba7b51a78f

STIX ID: report--8723cf6a-2b62-536e-a958-17ba7b51a78f

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Guru Baran

...
...

High-severity vulnerabilities (CVE-2026-12957 and CVE-2026-12958) in Amazon Q developer extensions allowed attacker-controlled MCP configs in .amazonq/mcp.json to be auto-executed when a developer opened a repository, enabling arbitrary code execution and exfiltration of AWS credentials, API keys, and other secrets across multiple IDE plugins; Amazon released patches and guidance to update plugins and treat untrusted repositories cautiously.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.