2026 047 Aws
Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:00 AM PDT
Language Servers for AWS provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and Visual Studio).
We identified CVE-2026-12957 , an improper trust boundary enforcement issue in Language Servers for AWS before version 1.65.0. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.
We identified CVE-2026-12958 , a missing symlink-validation issue in Language Servers for AWS before version 1.69.0. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.
These issues affect the Amazon Q Developer IDE plugins, which bundle Language Servers for AWS. Both issues are remediated in Language Servers for AWS version 1.69.0.
Affected products & versions:
These issues have been addressed in Language Servers for AWS version 1.69.0 and the corresponding Amazon Q Developer plugin releases that bundle it. We recommend upgrading to the latest version of your Amazon Q Developer IDE plugin, and ensuring any forked or derivative code is patched to incorporate the new fixes.
No workarounds are available.
We would like to thank Wiz for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email [email protected] with any security questions or concerns.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
