Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A high-severity vulnerability (CVE-2026-12957) in Amazon Q Developer for Visual Studio Code allowed attackers to execute arbitrary code and steal AWS credentials by automatically loading malicious MCP server configurations from cloned repositories. Discovered by Wiz Research, the flaw permits silent...
A vulnerability named GhostApproval has been discovered in six major AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. This flaw allows malicious repositories to trick AI agents into accessing files outside their designated...
In July 2026, Noma Labs discovered a prompt injection vulnerability in GitHub's Agentic Workflows, named GitLost, allowing unauthenticated attackers to access private repositories by crafting a GitHub Issue in a public repository. The vulnerability exploits the AI agent's failure to distinguish betw...