logo

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

ID: 0210a5fd-f957-5d7e-811f-05085ae510e0

STIX ID: report--0210a5fd-f957-5d7e-811f-05085ae510e0

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: [email protected] (The Hacker News)

...
...

A high-severity flaw (CVE-2026-12957, CVSS 8.5) in Amazon Q’s handling of MCP config allowed a repo-provided .amazonq/mcp.json to launch processes that inherited developers' environment (including AWS keys and CLI tokens), enabling credential theft and potential cloud compromise; Wiz disclosed a PoC and AWS patched the Language Servers for AWS across VS Code, JetBrains, Eclipse, and Visual Studio (updates recommended).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.