VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_1fc5c8704160b449bddf3ad432079a15

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

Published Jun 26, 2026

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it.

Tracked as CVE-2026-12957 (CVSS 8.5), the bug sat in how Amazon's AI coding assistant handled Model Context Protocol (MCP) servers.

Wiz

Affected AI Products

model context protocol
Get the weekly digest. Every Monday: top AI security stories of the week. Free.