CVE-2026-12957 is a vulnerability tracked across 2 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed June 26, 2026; most recent activity July 9, 2026.
A high-severity vulnerability (CVE-2026-12957) in Amazon Q Developer for Visual Studio Code allowed attackers to execute arbitrary code and steal AWS credentials by automatically loading malicious MCP server…
A vulnerability named GhostApproval has been discovered in six major AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. This flaw allows…