Skip to content
Amazon Q vulnerability allowed malicious Git repositories to steal cloud credentials

Amazon Q vulnerability allowed malicious Git repositories to steal cloud credentials

Feeds.4Sysops IT News June 26, 2026

A high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code allowed attackers to execute arbitrary code on a developer's workstation. The flaw, tracked as CVE-2026-12957, stemmed from the automatic loading of Model Context Protocol (MCP) configurations found within a repository's hidden directory. When a developer opened a booby-trapped project and activated the AI assistant, the extension executed commands defined in the configuration file without requesting user consent. Source