INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Amazon Q Developer Flaw Could Let Malicious Repos Run Code

| 2026-06-26 15:34 CRITICAL MEDIUM VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A high-severity flaw in Amazon's AI coding assistant for Visual Studio Code, tracked as CVE-2026-12957 and assigned a CVSS 4.0 score of 8.5, was discovered on June 26, 2026. Researchers from Wiz found that the extension would automatically load a repository's .amazonq/[IOC HIDDEN • LOGIN REQUIRED] file and execute commands it contained when a developer opened the project and activated Amazon Q, potentially allowing an attacker to execute code on a developer's machine and gain access to their cloud environment. The bug affected many AI coding assistants adopting Model Context Protocol (MCP) server configurations, which allowed malicious repositories to run arbitrary commands with full access to the developer's credentials. Wiz built a repository with a malicious MCP configuration that executed a command against AWS using the developer's existing credentials when opened and activated Amazon Q, demonstrating the attack's feasibility.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-30615, CVE-2025-54136 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

mc•••••.json
1.94.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-30615CVE-2026-30615 CVE-2025-54136CVE-2025-54136 CVE-2026-12958CVE-2026-12958 CVE-2025-59536CVE-2025-59536 CVE-2026-12957CVE-2026-12957
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2026/06/26
Threat actors exploited a high-severity flaw in Amazon's AI coding assistant, tracked as CVE-2026-12957, which allowed them to execute code on a developer's machine by opening an open Git repository.
infrastructure 1.65.0
infrastructure 1.69.0
infrastructure Vs Code
infrastructure 2.20
infrastructure 4.3
infrastructure 2.7.4
infrastructure 1.94.0
data_breach 2.20 JetBrains
infrastructure 4.3 Eclipse
infrastructure Cursor
infrastructure Windsurf
infrastructure Visual Studio Code
Tactical Metrics
Metrics
infrastructure
‎Vs Code
Affected Product
Metrics
infrastructure
‎1.65.0
Software Version
Metrics
infrastructure
‎1.69.0
Software Version
Metrics
infrastructure
‎2.20
Software Version
Metrics
infrastructure
‎4.3
Software Version
Metrics
infrastructure
‎2.7.4
Software Version
Metrics
infrastructure
‎1.94.0
Software Version
Metrics
data_breach
2
Jetbrains
Metrics
infrastructure
4
Eclipse
Metrics
infrastructure
‎Cursor
Affected Product
Metrics
infrastructure
‎Windsurf
Affected Product
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Intelligence Sources
The Register - Cybercrime 2026-06-26