Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments
ID: 8723cf6a-2b62-536e-a958-17ba7b51a78f
STIX ID: report--8723cf6a-2b62-536e-a958-17ba7b51a78f
Feed Name: cybersecurityNews.com
Threat Score
High-severity vulnerabilities (CVE-2026-12957 and CVE-2026-12958) in Amazon Q developer extensions allowed attacker-controlled MCP configs in .amazonq/mcp.json to be auto-executed when a developer opened a repository, enabling arbitrary code execution and exfiltration of AWS credentials, API keys, and other secrets across multiple IDE plugins; Amazon released patches and guidance to update plugins and treat untrusted repositories cautiously.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
