INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Amazon Q Developer Flaw Could Let Malicious Repos Run Code
| 2026-06-26 15:34 CRITICAL MEDIUM VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A high-severity flaw in Amazon's AI coding assistant for Visual Studio Code, tracked as CVE-2026-12957 and assigned a CVSS 4.0 score of 8.5, was discovered on June 26, 2026. Researchers from Wiz found that the extension would automatically load a repository's .amazonq/[IOC HIDDEN • LOGIN REQUIRED] file and execute commands it contained when a developer opened the project and activated Amazon Q, potentially allowing an attacker to execute code on a developer's machine and gain access to their cloud environment. The bug affected many AI coding assistants adopting Model Context Protocol (MCP) server configurations, which allowed malicious repositories to run arbitrary commands with full access to the developer's credentials. Wiz built a repository with a malicious MCP configuration that executed a command against AWS using the developer's existing credentials when opened and activated Amazon Q, demonstrating the attack's feasibility.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-30615, CVE-2025-54136 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
mc•••••.json
1.94.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-30615CVE-2026-30615
CVE-2025-54136CVE-2025-54136
CVE-2026-12958CVE-2026-12958
CVE-2025-59536CVE-2025-59536
CVE-2026-12957CVE-2026-12957
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
2026/06/26
Threat actors exploited a high-severity flaw in Amazon's AI coding assistant, tracked as CVE-2026-12957, which allowed them to execute code on a developer's machine by opening an open Git repository.
Click on any entity below to view its context and source!
infrastructure
1.65.0
CVE-2026-12957 is fixed in Language Servers for AWS 1.65.0, but AWS's
bulletin
tells customers to move to 1.69.0.
Amazon fixed the bug in version 1.65.0 of its language server, which powers Amazon Q's IDE integrations.
We have remediated this issue in language server version 1.65.0," Amazon said in an
advisory
, though it didn't respond to
The Register's
questions.
infrastructure
1.69.0
CVE-2026-12957 is fixed in Language Servers for AWS 1.65.0, but AWS's
bulletin
tells customers to move to 1.69.0.
infrastructure
Vs Code
The flaw lives in
Language Servers for AWS
, the runtime that powers Amazon Q across VS Code, JetBrains, Eclipse, and Visual Studio.
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls th…
infrastructure
2.20
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls th…
infrastructure
4.3
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls th…
infrastructure
2.7.4
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls th…
infrastructure
1.94.0
…ed plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls the latest…
data_breach
2.20 JetBrains
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls the…
infrastructure
4.3 Eclipse
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls the…
infrastructure
Cursor
Claude Code
(CVE-2025-59536) and
Cursor
(CVE-2025-54136) both had project-level MCP config that led to command execution.
infrastructure
Windsurf
Windsurf
(CVE-2026-30615) reached the same end by a different path, with attacker-controlled content rewriting the local MCP config to register a malicious server.
infrastructure
Visual Studio Code
…assistants now execute commands from project configurations
A high-severity flaw in Amazon's AI coding assistant for Visual Studio Code meant that opening the wrong Git repository could allow an attacker to execute code on a developer's mach…
Tactical Metrics
Metrics
infrastructure
Vs Code
Affected Product
Click for context!
The flaw lives in
Language Servers for AWS
, the runtime that powers Amazon Q across VS Code, JetBrains, Eclipse, and Visual Studio.
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls th…
Metrics
infrastructure
1.65.0
Software Version
CVE-2026-12957 is fixed in Language Servers for AWS 1.65.0, but AWS's
bulletin
tells customers to move to 1.69.0.
Amazon fixed the bug in version 1.65.0 of its language server, which powers Amazon Q's IDE integrations.
We have remediated this issue in language server version 1.65.0," Amazon said in an
advisory
, though it didn't respond to
The Register's
questions.
Metrics
infrastructure
1.69.0
Software Version
CVE-2026-12957 is fixed in Language Servers for AWS 1.65.0, but AWS's
bulletin
tells customers to move to 1.69.0.
Metrics
infrastructure
2.20
Software Version
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls th…
Metrics
infrastructure
4.3
Software Version
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls th…
Metrics
infrastructure
2.7.4
Software Version
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls th…
Metrics
infrastructure
1.94.0
Software Version
…ed plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls the latest…
Metrics
data_breach
2
Jetbrains
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls the…
Metrics
infrastructure
4
Eclipse
The patched plugin minimums:
VS Code: 2.20 or later
JetBrains: 4.3 or later
Eclipse: 2.7.4 or later
Visual Studio toolkit: 1.94.0.0 or later
The language server auto-updates unless the network blocks it, and reloading the IDE pulls the…
Metrics
infrastructure
Cursor
Affected Product
Claude Code
(CVE-2025-59536) and
Cursor
(CVE-2025-54136) both had project-level MCP config that led to command execution.
Metrics
infrastructure
Windsurf
Affected Product
Windsurf
(CVE-2026-30615) reached the same end by a different path, with attacker-controlled content rewriting the local MCP config to register a malicious server.
Metrics
infrastructure
Visual Studio Code
Affected Product
…assistants now execute commands from project configurations
A high-severity flaw in Amazon's AI coding assistant for Visual Studio Code meant that opening the wrong Git repository could allow an attacker to execute code on a developer's mach…
Intelligence Sources
The Hacker News
2026-06-26
The Register - Cybercrime
2026-06-26
Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds
The Register - Cybercrime
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:44
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
MCP
entity
6x
timeline
Temporal Reference
Jun 26, 2026
date
6x
infrastructure
Software Version
1.65.0
version
5x
vulnerability
Exploited CVE
CVE-2026-12957
cve
4x
infrastructure
Affected Product
Vs Code
software
2x
vulnerability
CVSS Score
8
score
Contextual Telemetry
Context Block
6 METRICS
data breach
Jetbrains
2
jetbrains
infrastructure
Eclipse
4
eclipse
attribution
Attributing Entity
CVE-2026
authority
general metric
Jun
26
jun
target region
Target Country
United States
country
general metric
Score
4
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.