Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer’s cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it.

Tracked as CVE-2026-12957 (CVSS 8.5), the bug sat in how Amazon’s AI coding assistant handled Model Context Protocol (MCP) servers.

Wiz

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Quality non-fiction books are the antithesis of AI slop

Quality non-fiction books are the antithesis of AI slop Source: Hacker News

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader

AI Boosts Research Careers but Flattens Scientific Discovery

AI Boosts Research Careers but Flattens Scientific Discovery Source: Hacker News