Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer’s cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it.

Tracked as CVE-2026-12957 (CVSS 8.5), the bug sat in how Amazon’s AI coding assistant handled Model Context Protocol (MCP) servers.

Wiz

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing

Computer-Aided Language Development in Nonspeaking Children (1968) [pdf]

Computer-Aided Language Development in Nonspeaking Children (1968) [pdf] Source: Hacker News

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and