www.securityweek.com 6/26/2026, 3:31:57 PM · external

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories

Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
Developing story vulnerability 2 articles tracked
Amazon Q Developer flaw (CVE-2026-12957) allows credential theft via malicious repositories
CyberSIXT Evidence Panel
Primary Source aws.amazon.com
CISA KEV Not in KEV
Patch Patch Status Unknown

RESEARCHERS at Wiz identified a high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code that could enable attackers to steal cloud credentials by exploiting malicious code repositories. This vulnerability allows unauthorized commands to run automatically when opening a compromised repository, risking cloud sessions and credentials. AWS released a patch for this issue (CVE-2026-12957) on May 12 after being notified on April 20.

The fix is available for various IDEs including VS Code and JetBrains. Wiz noted that similar vulnerabilities exist in other AI coding tools, highlighting a widespread security concern.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline