Skip to main content
← Back to sources

CVE-2026-12957: Amazon Q Developer Auto-Executes Untrusted MCP Configs — Same Config-Trust Flaw Class Hitting Claude Code, Cursor, and Windsurf

Published 2026-06-26Ingested 2026-06-30AI Engineering PracticesHigh

Summary

Wiz Research publicly disclosed CVE-2026-12957 (and related CVE-2026-12958) on June 26, 2026, a high-severity flaw in the Amazon Q Developer extension for VS Code. The extension automatically loaded a workspace's `.amazonq/mcp.json` MCP-server configuration and executed the commands it contained — with no consent prompt, no workspace-trust check, and full inheritance of the developer's environment. Cloning a malicious repository and opening it with Amazon Q active was enough to run attacker-cont

Radar Context

Alignment: Reinforces current position
Related Positions: AI-Assisted Development Tooling, AI Governance and Risk, Agentic Workflows
Related Partnerships: Anthropic (Claude), Microsoft (GitHub / Copilot), Cognition (Windsurf / Devin)
cvemcpai-coding-securityamazon-qclaude-codesupply-chainworkspace-trustcredential-theftagentic-tooling