Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
- Posted on June 26, 2026
- By The Hacker News
- 0 Views
- 1 min read
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
Amazon patched CVE-2026-12957, a high-severity Amazon Q Developer flaw that let malicious MCP config run commands and steal AWS credentials.