CVE-2026-12958Patch

LOWCVSS 8.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users should upgrade to version 1.69.0 or higher.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-06-23); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-06-23: 1Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-07-03: 1Mentions · 2026-09-07: 1PoC Mentioned / Linked · 2026-06-26: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-09-07: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-03: 1Technical Details · 2026-09-07: 106-2306-2506-2607-0309-07
Signal classification3 categories
Patch
360.0%
General
120.0%
Disclosure
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-231
Patch1
2026-06-251
General1
2026-06-261
Patch1
2026-07-031
Disclosure1
2026-09-071
Patch1
Full discourse5 posts
  • iototsecnews@iototsecnews
    Disclosure

    Amazon Q Developer の脆弱性 CVE-2026-12957/12958 が FIX:任意のコード実行と AWS 認証情報窃取の恐れ https://iototsecnews.jp/2026/06/27/amazon-q-developer-vulnerability-allows-code-execution-via-malicious-repositories/ 脆弱性 CVE-2026-12957/CVE-2026-12958 は、AI が設定ファイルを読み込む際の確認不足に起因するものである。Amazon Q の仕組みにより、開発者の許可や確認なしに、ワークスペース内にある設定ファイルが自動で実行され、危険なコマンドが動作する状態になっていました。その結果として、プロジェクトを開くだけで、大切なクラウドの認証情報やシステムへのアクセス権が攻撃者に盗まれてしまう可能性が生じています。AI ツールは便利ですが、外部からダウンロードしたフォルダを安易に開くと、意図しない設定が勝手に実行されるリスクがあることを知っておく必要があります。ご利用のチームは、十分に ご注意ください。 #Uncategorized

    Post summary

    Amazon Q Developer is vulnerable to automatic execution of malicious configuration files (CVE‑2026‑12957/12958), allowing arbitrary code execution and possible AWS credential theft. No evidence of active exploitation or publicly available exploit code is reported; only the vulnerability details and precautionary advice are disclosed.

    01001189
    501 followersView on X
  • Peldum@peldumHack
    Patch

    4/5 Los 6 (según Wiz, 8 jul 2026): • Amazon Q → CVE-2026-12958 · parcheado (lang server ≥1.69.0) • Cursor → CVE-2026-50549 Critical · parcheado (v3.0+) • Google Antigravity → Critical · parcheado (mayo 2026) • Claude Code → Anthropic lo disputó (“fuera del threat model”); hay warning de symlink • Augment y Windsurf → al disclosure, sin parche En Windsurf/Amazon Q el write a veces iba *antes* del Accept: el “OK” era un undo, no un candado.

    Post summary

    The tweet enumerates several CVEs, provides patch availability and version details for most, notes a vendor dispute over one (Claude Code) and a symlink warning, and does not mention PoC, exploit tools, or active exploitation.

    1000066
    580 followersView on X
  • GoCocoaAI@GoCocoaAI
    Patch

    Sources for the above — all verified: Wiz Research technical disclosure (June 26, 2026), including PoC detail, CVE table across affected AI coding tools, and MITRE mapping: https://www.wiz.io/blog/amazon-q-vulnerability AWS Security Bulletin 2026-047 (June 23, 2026), covering both CVE-2026-12957 and CVE-2026-12958 with fixed version matrix across all four IDEs: https://aws.amazon.com/security/security-bulletins/2026-047-aws/ SecurityWeek write-up (June 26, 2026): https://www.securityweek.com/amazon-q-flaw-enabled-cloud-credential-theft-via-malicious-repositories/

    Post summary

    Wiz Research disclosed a PoC of a cloud credential theft flaw affecting Amazon Q IDEs, and AWS released patched versions for the identified CVEs; no active exploitation is reported.

    0000057
    34 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    General

    CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins http://dlvr.it/TTChDY #patchmanagement

    Post summary

    The tweet merely announces two CVEs affecting language servers in AWS and Amazon Q Developer Plugins, without providing additional technical or exploitation details.

    0000059
    2.0K followersView on X
  • Israel@f1tym1
    Patch

    AWS patched CVE-2026-12957 and CVE-2026-12958 in Language Servers for AWS and Amazon Q Developer IDE plugins. https://ift.tt/MgR9pkx

    Post summary

    AWS announced the release of patches for CVE‑2026‑12957 and CVE‑2026‑12958 affecting its Language Server in Amazon Q Developer IDE plugins; no exploitation details or PoC were mentioned.

    0000074
    1.0K followersView on X

Explore more