CVE-2026-12957Disclosure

MEDIUMCVSS 8.5 · HIGH

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted. To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 37 mentions across 14 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 26 signals
  • Disclosure: 14 classified signals
  • General: 5 classified signals
  • Peaked 11d ago at 10 mentions (2026-06-26); latest day: 1
  • 37 total mentions across 14 days

Deep dive

Activity timeline37 mentions / 14d
035810Mentions · 2026-06-23: 2Mentions · 2026-06-25: 1Mentions · 2026-06-26: 10Mentions · 2026-06-27: 8Mentions · 2026-06-28: 3Mentions · 2026-06-29: 3Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-03: 3Mentions · 2026-07-05: 1Mentions · 2026-07-07: 1Mentions · 2026-07-12: 1Mentions · 2026-07-21: 1Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-06-26: 2PoC Mentioned / Linked · 2026-06-27: 1PoC Mentioned / Linked · 2026-07-21: 1Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-07-01: 1Patch / Workaround · 2026-06-23: 2Patch / Workaround · 2026-06-26: 5Patch / Workaround · 2026-06-27: 3Patch / Workaround · 2026-06-28: 2Patch / Workaround · 2026-06-29: 2Patch / Workaround · 2026-07-03: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-26: 8Technical Details · 2026-06-27: 7Technical Details · 2026-06-28: 3Technical Details · 2026-06-29: 2Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-07: 106-2306-2506-2606-2706-2806-2906-3007-0107-0307-0507-0707-1207-2108-21
Signal classification6 categories
Disclosure
1437.8%
Patch
1335.1%
General
513.5%
PoC
25.4%
Active Exploitation
25.4%
Exploit
12.7%
Referenced assets28 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-232
Patch2
2026-06-251
Disclosure1
2026-06-2610
Disclosure5Patch5
2026-06-278
Disclosure3General1Patch3PoC1
2026-06-283
Disclosure1General1Patch1
2026-06-293
Active Exploitation1Patch2
2026-06-301
Disclosure1
2026-07-011
Active Exploitation1
2026-07-033
Disclosure1General2
2026-07-051
Exploit1
2026-07-071
Disclosure1
2026-07-121
Disclosure1
2026-07-211
PoC1
2026-08-211
General1
Full discourse20 posts
  • Michael Lopez Chiesa@PenQuester
    Active Exploitation

    🚨 The number to watch in AI security isn't discovery. It's verification. Three AI-security stories hit the feed this week and they look like they're arguing. They're not. 🔎 1️⃣ : a flaw in Amazon Q (CVE-2026-12957) let a booby-trapped code repo auto-run hostile commands and walk off with cloud credentials. Open the wrong repo, the agent does exactly what it was built to do, reads project context and acts on it, except the context was poisoned. Similar flaws hit Claude Code, Cursor, and Windsurf the same week. That's not one vendor being sloppy. That's the category. 2️⃣ : AI is genuinely, categorically good at finding vulnerabilities. One coalition surfaced 20,000+ findings across 500 projects. The flaws were always there. We finally built something patient enough to look at all of it. 3️⃣ : confidence in *fully autonomous* AI pentesting dropped to 9%, down from 29% a year ago. The honest read isn't "AI declined." People ran it long enough to learn where it fails, and adjusted. That's the system working. Here's the takeaway for leaders. AI is a force multiplier, and the word doing the work is *multiplier*. You can buy discovery for almost nothing now. You can't buy senior judgment at the same rate. If your AI's output outruns your team's ability to verify it, you didn't add security. You added an unverified backlog wearing a security costume. 🧠 Keep your verification capacity ahead of your discovery rate. That ratio is the whole game. Sources: https://www.theregister.com/cyber-crime/2026/06/26/amazon-q-flaw-let-booby-trapped-git-repos-execute-code-swipe-cloud-creds/5263202 https://www.theregister.com/security/2026/06/27/its-looking-like-a-hot-messy-summer-for-security-teams-as-ai-finds-countless-previously-hidden-vulns/5260478 https://www.darkreading.com/cybersecurity-operations/ai-decline-confidence-autonomous-penetration-testing Wrote about why this matters → https://medium.com/@penquestr #AISecurity #Cybersecurity #AI #InfoSec #TechNews

    Post summary

    The post confirms that CVE‑2026‑12957 was actively exploited in Amazon Q to run malicious code and exfiltrate cloud credentials, but it provides no PoC, patch, or exploit tool details.

    51064301.5K
    689 followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🛑 Opening a repo shouldn't hand over your AWS keys. Amazon patched CVE-2026-12957, an #Amazon Q Developer flaw that let a malicious repo run code the moment you open and trust the workspace, with the developer's cloud credentials already attached. No separate MCP approval. No second sign-in. Learn how the attack worked 🠖 https://thehackernews.com/2026/06/amazon-q-developer-flaw-could-let.html

    Post summary

    Amazon has applied a patch to CVE‑2026‑12957, a flaw that allowed malicious code execution with attached AWS credentials, but the text provides no evidence of active exploitation or an available PoC.

    3172591220.4K
    2.2M followersView on X
  • Wiz@wiz_io
    Patch

    🚨Wiz Research update: MCP Auto-Execution: From Git Clone to Cloud Compromise. This let malicious repos run code and steal AWS credentials without consent via workspace MCP configs. Attackers could compromise cloud envs. Fixed in language server 1.65.0 (CVE-2026-12957). https://www.wiz.io/blog/amazon-q-vulnerability

    Post summary

    Wiz Research announced a vulnerability (CVE-2026-12957) that allows malicious Git repositories to run code, steal AWS credentials via workspace MCP configurations; the issue is resolved in language server 1.65.0.

    18124125.2K
    25.3K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『Combined with full environment inheritance, this enabled immediate code execution.』😨 CVE-2026-12957 MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension https://www.wiz.io/blog/amazon-q-vulnerability

    Post summary

    The snippet announces CVE‑2026‑12957, highlighting code execution via environment inheritance in the Amazon Q VS Code Extension, but offers no PoC, exploit code, or patch details.

    00012457
    6.9K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Amazon Q Developer の脆弱性 CVE-2026-12957/12958 が FIX:任意のコード実行と AWS 認証情報窃取の恐れ https://iototsecnews.jp/2026/06/27/amazon-q-developer-vulnerability-allows-code-execution-via-malicious-repositories/ 脆弱性 CVE-2026-12957/CVE-2026-12958 は、AI が設定ファイルを読み込む際の確認不足に起因するものである。Amazon Q の仕組みにより、開発者の許可や確認なしに、ワークスペース内にある設定ファイルが自動で実行され、危険なコマンドが動作する状態になっていました。その結果として、プロジェクトを開くだけで、大切なクラウドの認証情報やシステムへのアクセス権が攻撃者に盗まれてしまう可能性が生じています。AI ツールは便利ですが、外部からダウンロードしたフォルダを安易に開くと、意図しない設定が勝手に実行されるリスクがあることを知っておく必要があります。ご利用のチームは、十分に ご注意ください。 #Uncategorized

    Post summary

    Amazon Q Developer vulnerabilities CVE-2026-12957/12958 allow arbitrary code execution and AWS credential theft due to insecure configuration handling; a fix has been released.

    01001189
    501 followersView on X
  • Halil Deniz@denizhalilT
    Disclosure

    difa just claimed Exploiting Language Servers for AWS: Deep Dive into Command Injection (CVE-2026-12957) on my @buymeacoffee. You can also claim it here https://www.buymeacoffee.com/halildeniz/c/19100701

    Post summary

    The post announces a claim of an exploit for CVE‑2026‑12957 involving command injection in AWS language servers, but does not provide actual PoC code, patches, or evidence of active exploitation.

    0002062
    32 followersView on X
  • Halil Deniz@denizhalilT
    General

    difa just claimed Exploiting Language Servers for AWS: Deep Dive into Command Injection (CVE-2026-12957) on my @buymeacoffee. You can also claim it here https://www.buymeacoffee.com/halildeniz/c/19100679

    Post summary

    The text claims a user has exploited a command‑injection vulnerability (CVE‑2026‑12957) in AWS language servers, but offers no proof, PoC, or technical detail beyond the vulnerability type.

    0002046
    32 followersView on X
  • SoEmailSecurity@Soemailsecurity
    Patch

    CVE-2026-12957 exposed Amazon Q Developer users to code execution & credential theft via MCP configs. Now patched, but what other hidden flaws are waiting to be found? Protect your inbox: http://soemailsecurity.com #cloudsecurity #devsecurity #emailprotection

    Post summary

    CVE-2026-12957 allowed code execution and credential theft through MCP configurations on Amazon Q Developer, has been patched, and no active exploitation or PoC is reported.

    1001063
    67 followersView on X
  • Halil Deniz@denizhalilT
    PoC

    okiech just claimed Exploiting Language Servers for AWS: Deep Dive into Command Injection (CVE-2026-12957) on my @buymeacoffee. You can also claim it here https://www.buymeacoffee.com/halildeniz/c/19405105

    Post summary

    The post presents a Proof of Concept for CVE-2026-12957, linking to a page where the PoC is hosted, but does not provide exploit code, active exploitation evidence, patches, or technical details.

    0001036
    33 followersView on X
  • CloudSecurityAlliance@cloudsa
    General

    CISO Daily Briefing: Amazon Q Developer CVE-2026-12957 (CVSS 8.5) — MCP auto-execution, no user interaction required, Miasma worm across 73 GitHub repos; Linux LPEs CVE-2026-46331 + CVE-2026-43503 bypass file integrity monitoring entirely in memory. Fable 5/Mythos 5 suspended for foreign nationals under export controls — no appeals timeline. GPT-5.6 Sol matches Mythos on ExploitBench at 1/3 token cost — no public safety evaluation methodology published. https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260628/

    Post summary

    The briefing presents technical details on several Amazon Q Developer and Linux CVEs, noting worm presence and LPE mechanisms, but offers no PoC, exploit code, active exploitation claims, or patch information.

    00001531
    18.8K followersView on X
  • Glitch News@glitch4techs
    Disclosure

    ثغرة Amazon Q Developer الحرجة: اختراق بيانات المطورين وسرقة صلاحيات AWS 🚀 النظرة العامة: تم الكشف عن ثغرة عالية الخطورة (CVE-2026-12957) في Amazon Q Developer، تسمح للمستودعات الخبيثة بتنفيذ تعليمات برمجية وسرقة بيانات اعتماد المطورين السحابية بمجرد استنساخ مشروع. أمازون قامت بتصحيحها في Language Servers for AWS 1.69.0. 🛠 التحليل التقني: تكمن المشكلة في طريقة تعامل Amazon Q مع ملفات تكوين Model Context Protocol (MCP)، حيث يمكن لملف `.amazonq/mcp.json` في المستودع تشغيل عمليات محلية ترث بيئة المطور الكاملة (مفاتيح AWS، أسرار API). هذا يسمح للمهاجمين بالوصول إلى جلسات AWS الحية. 🎯 لماذا يهمك هذا؟ هذه الثغرة تسلط الضوء على مخاطر الثقة الضمنية في أدوات الذكاء الاصطناعي ومكونات سلسلة التوريد البرمجية. يجب على المطورين تحديث إضافات IDE الخاصة بهم فورًا (VS Code 2.20+, JetBrains 4.3+, Eclipse 2.7.4+, Visual Studio 1.94.0.0+) والتدقيق في المستودعات لتعزيز أمن بيئاتهم. #Glitch4Techs #أمن_المعلومات #ذكاء_اصطناعي #تطوير_برمجيات #Amazon 🔗 اقرأ المقال كاملاً عبر موقعنا: اضغط هنا للمتابعة والقراءة

    Post summary

    The post discloses CVE-2026-12957 in Amazon Q Developer, details how malicious repo files can exfiltrate AWS credentials, and recommends applying Amazon’s patch and updating IDE plugins.

    10000134
    24 followersView on X
  • Halil Deniz@denizhalilT
    PoC

    🚨 Alert for Amazon Q Developer users! CVE-2026-12957 in Language Servers for AWS allows zero-click command injection simply by opening a malicious repository, risking cloud credential theft. Dive into my full technical analysis: https://denizhalil.com/2026/06/27/cve-2026-12957-aws-language-server-command-injection/ https://t.co/IxmuFxr1CI

    Post summary

    The tweet highlights a zero-click command injection in Amazon Q Developer's language server (CVE‑2026‑12957) and links to a technical analysis that likely contains a proof of concept, but it makes no claims of active exploitation or available patches.

    0001050
    32 followersView on X
  • CyberTLDR@CyberTLDR
    Patch

    1/3 A high-severity flaw in Amazon Q Developer let a malicious repo run commands and steal a developer's cloud credentials just by being opened. CVE-2026-12957 (CVSS 8.5), found by Wiz Research, is now patched. #CVE #AmazonQ #AWS #SupplyChainAttack #cybersecurity

    Post summary

    A high‑severity flaw (CVE‑2026‑12957) in Amazon Q Developer allowed command execution via a malicious repository, but the issue has already been patched.

    1000075
    15 followersView on X
  • CyberTLDR@CyberTLDR
    Patch

    1/3 Amazon Q Developer had a high severity flaw, CVE-2026-12957, CVSS 8.5. A malicious repo could plant an MCP config file and run commands the moment a developer opened the workspace, reaching cloud credentials. Amazon has patched it. #AmazonQ #AWS #AI #cybersecurity

    Post summary

    Amazon Q Developer’s CVE-2026-12957, a high‑severity flaw affecting MCP config handling, has been patched by Amazon; no proof‑of‑concept or active exploitation details are provided.

    1000077
    14 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-12957: Language Servers for AWS Trust Boundary Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04tWdzX0

    Post summary

    The post references the disclosed CVE-2026-12957 concerning AWS trust boundary issues but does not provide any concrete proof‑of‑concept, exploit, or patch details.

    0000018
    33 followersView on X
  • @pedri77@pedri77
    Disclosure

    CVE-2026-12957 in Amazon Q is the third MCP auto-execution vulnerability in three AI coding tools. The pattern reveals a shared design failure, not just a single vendor mistake. Amazon Q’s MCP Flaw Is an Industry Warnin... https://f.mtr.cool/mobzorkkzs

    Post summary

    CVE-2026-12957, a third MCP auto‑execution flaw in Amazon Q, has been disclosed, underscoring a shared design failure across multiple AI coding tools.

    0000054
    2.1K followersView on X
  • Marcin Brzózka@marcin_brz81183
    Disclosure

    New MCP security coverage on MCPwatch: Amazon Q Developer MCP auto-execution CVE-2026-12957, Agentjacking attack patterns, and IDE/plugin supply-chain risk. https://www.mcpwatch.tech/mcp-attacks-developer-ides-amazon-q-agentjacking/

    Post summary

    The tweet announces coverage of a new Amazon Q Developer vulnerability (CVE‑2026‑12957) with a focus on auto‑execution issues, agentjacking patterns, and supply‑chain risk, but it lacks any PoC, exploitation code, or evidence of active attacks.

    0000063
    21 followersView on X
  • Martin Musiol@musiol_martin
    Exploit

    Amazon Q Developer will run commands from a malicious repo and hand over your cloud credentials. CVE-2026-12957, CVSS 8.5, via its MCP handling. Second AI coding tool this week, same root cause: untrusted text reaching a shell. That's a pattern, not a bug. https://nvd.nist.gov/vuln/detail/CVE-2026-12957

    Post summary

    Amazon Q Developer can execute commands from a malicious repository, resulting in the leaking of cloud credentials via untrusted text reaching a shell; the vulnerability is rated CVSS 8.5.

    00000110
    402 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 55% of vulnerabilities from past week, CVE-2026-12957 has 9 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post notes that CVE-2026-12957 has received multiple online articles, but it provides no details on exploitation, patches, or technical aspects.

    0000064
    75 followersView on X
  • Artisan@TechZeitGeist
    General

    Amazon Q Developer: CVE-2026-12957 macht MCP-Konfigurationen riskant Kurz gesagt: CVE-2026-12957 rückt Amazon Q Developer… https://www.techzeitgeist.de/amazon-q-developer-cve-2026-12957-macht-mcp-konfigurationen-riskant/ #TechNews #Digitalisierung

    Post summary

    The brief snippet mentions the CVE identifier but contains no substantive details, proofs, or actions related to it.

    0000067
    151 followersView on X

Explore more