Amazon Q Developer Flaw Allowed Code Execution and Credential Theft
A high-severity vulnerability (CVE-2026-12957, CVSS 8.5) in Amazon Q Developer allowed malicious repositories to execute arbitrary commands and steal cloud credentials. The flaw exploited how Amazon’s AI coding assistant handled Model Context Protocol (MCP) servers. A developer merely opening and trusting a malicious workspace could lead to compromise. Amazon has since patched the vulnerability.