Skip to main content

Share story

Security

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs Image: Primary
Amazon has fixed a high-severity vulnerability in Amazon Q Developer that allowed malicious repositories to execute code and exfiltrate cloud credentials through Model Context Protocol configurations. The Hacker News reported June 26 that the flaw, tracked as CVE-2026-12957 with a CVSS score of 8.5, was found by Wiz Research. The bug was in how the AI coding assistant handled MCP servers defined in a .amazonq/mcp.json file placed in an opened workspace. Amazon Q read the file and launched the servers, which inherited the developer's full environment, including AWS keys, cloud CLI tokens, API secrets and SSH agent sockets. A single config file in a cloned repo was enough to reach this state once the workspace was trusted. In a proof of concept, Wiz showed the file could run aws sts get-caller-identity and send the output to an attacker server. Amazon said users must trust the workspace when prompted. Wiz said there was no separate consent step for the MCP servers before the fix. The patch now flags untrusted MCP servers and lets developers reject them. The flaw was in Language Servers for AWS, used by Amazon Q in VS Code, JetBrains, Eclipse and Visual Studio. It is fixed in Language Servers for AWS version 1.69.0. Minimum plugin versions are VS Code 2.20 or later, JetBrains 4.3 or later, Eclipse 2.7.4 or later and Visual Studio 1.94.0.0 or later. No public exploitation is known. Wiz reported the issue April 20 and saw a fix May 12.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital AI
Capital AI

Enveda raises $311 million to advance AI-assisted drug candidates

Enveda has raised $311 million in Series E financing at a $2 billion valuation as it moves drug candidates found through its AI-assisted search of natural compounds into human testing. Catalio Capital Management led the round, wit...

Capital AI
Capital AI

Lightspeed targets $250 million for AI-focused India fund

Lightspeed is seeking $250 million for a new early-stage India fund focused on AI companies, with commitments for 80% of that target already secured, TechCrunch reported from a letter to investors. The proposed fund is half the si...

Science
Science

Infleqtion claims 30 entangled logical qubits on Sqale system

Infleqtion says it created 30 entangled logical qubits on its Sqale quantum computing system, a company-reported step toward operations across error-protected quantum bits. A logical qubit encodes information across multiple physi...

Capital AI
Capital AI

NUS Enterprise launches patent-matching platform and Munich outpost

NUS Enterprise says it has launched Nova, an AI platform developed with Zima Labs to help its staff find commercial partners for university research. It has also established an outpost in Munich through a partnership with Unterneh...

AI Policy
AI Policy

White House asks AI labs to delay model access for UK testers

The White House has asked OpenAI and Anthropic to keep new AI models from the UK's AI Security Institute until the US government tests them, Politico reported. A British official confirmed the reported request to Bloomberg. Politi...

AI Products
AI Products

Microsoft unveils Copilot app with coding and autonomous agents

Microsoft unveiled a redesigned Copilot app that brings chat, coding and autonomous agents into one interface for work. Its Home tab combines chat and task assistance, while Code is designed to create internal apps in a sandbox ho...