June 27, 2026
- Amazon Q Developer for VS Code (CVE-2026-12957, CVSS 8.5) let a malicious repository execute arbitrary commands and exfiltrate a developer's cloud credentials via untrusted MCP server configurations — opening the repo and trusting the workspace was enough. AWS has patched it and published an advisory. The Hacker News, SecurityWeek · AI & Model Security