Amazon Q Developer Vulnerability Enables Cloud Credential Theft

Amazon Q Developer Vulnerability Enables Cloud Credential Theft

First seen 26 Jun 2026, 16:23 UTC Theregisterwww.wiz.ioaws.amazon.comCybersecuritynewsThenextweb+5 88% similarity 74.0
Share:

Article Content

Browse articles
ThreatCluster

A high-severity vulnerability (CVE-2026-12957) in Amazon Q Developer for Visual Studio Code allowed attackers to execute arbitrary code and steal AWS credentials by automatically loading malicious MCP server configurations from cloned repositories. Discovered by Wiz Research, the flaw permits silent execution of commands without user consent, inheriting the developer's environment variables. Amazon patched the issue on May 12, 2026, but the public disclosure occurred on June 26, 2026. The vulnerability affects multiple IDEs, including Visual Studio Code, JetBrains, and Eclipse. Similar vulnerabilities have been reported in other AI coding tools, indicating a systemic risk in the development ecosystem. Users are advised to update to version 1.69.0 for comprehensive protection.

Key Points: • CVE-2026-12957 allows silent execution of malicious commands via Amazon Q Developer. • The vulnerability affects multiple IDEs and can lead to AWS credential theft. • Amazon released a patch on May 12, 2026, with public disclosure on June 26, 2026.

ThreatCluster AI

Timeline

2026-04-20
Wiz Research reports vulnerability to Amazon
Wiz disclosed the flaw allowing credential theft via malicious repositories to Amazon.
Thenextweb
2026-05-12
Amazon releases initial patch
Amazon patched the vulnerability in Language Servers for AWS version 1.65.0.
Cryptobriefing
2026-06-23
CVE-2026-12957 published
CVE-2026-12957 was officially published, detailing the vulnerability in Amazon Q Developer.
aws.amazon.com
2026-06-23
CVE-2026-12958 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-26
Public disclosure of vulnerability
The vulnerability was publicly disclosed, highlighting its severity and impact on developers.
Wiz Research

Community

Browse all →