Back Feeds.4Sysops Amazon Q vulnerability allowed malicious Git repositories to steal cloud credentials
A high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code allowed attackers to execute arbitrary code on a developer's workstation. The flaw, tracked as CVE-2026-12957, stemmed from the automatic loading of Model Context Protocol (MCP) configurations found within a repository's hidden directory. When a developer opened a booby-trapped project and activated the AI assistant, the extension executed commands defined in the configuration file without requesting user consent. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
