<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

AWS Fixes Amazon Q Flaw That Let Attackers Steal Cloud Credentials Silently

AWS patches a high-severity flaw in Amazon Q for VS Code, preventing credential theft from malicious repositories. Update now to protect data.
Content Team

AWS has patched a high-severity bug in the Amazon Q Developer extension for Visual Studio Code that could let attackers steal cloud credentials just by getting a developer to open a malicious repository. Tracked as CVE-2026-12957 and discovered by Wiz Research, the flaw allowed Amazon Q to automatically load and execute MCP server configurations without user approval — silently, before any code review happened.

Because spawned processes inherited the developer's full environment, attackers could grab AWS credentials, API keys, and SSH secrets. The fix landed in Language Server version 1.65.0. Similar MCP-related vulnerabilities have also been found in Claude Code, Cursor, and Windsurf.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo