
Amazon Q Developer の脆弱性 CVE-2026-12957/12958 が FIX:任意のコード実行と AWS 認証情報窃取の恐れ https://iototsecnews.jp/2026/06/27/amazon-q-developer-vulnerability-allows-code-execution-via-malicious-repositories/ 脆弱性 CVE-2026-12957/CVE-2026-12958 は、AI が設定ファイルを読み込む際の確認不足に起因するものである。Amazon Q の仕組みにより、開発者の許可や確認なしに、ワークスペース内にある設定ファイルが自動で実行され、危険なコマンドが動作する状態になっていました。その結果として、プロジェクトを開くだけで、大切なクラウドの認証情報やシステムへのアクセス権が攻撃者に盗まれてしまう可能性が生じています。AI ツールは便利ですが、外部からダウンロードしたフォルダを安易に開くと、意図しない設定が勝手に実行されるリスクがあることを知っておく必要があります。ご利用のチームは、十分に ご注意ください。 #Uncategorized
Post summary
Amazon Q Developer is vulnerable to automatic execution of malicious configuration files (CVE‑2026‑12957/12958), allowing arbitrary code execution and possible AWS credential theft. No evidence of active exploitation or publicly available exploit code is reported; only the vulnerability details and precautionary advice are disclosed.




