Summary

AWS disclosed CVE-2026-12957 and CVE-2026-12958 (Bulletin 2026-047) affecting Amazon Q Developer IDE plugins. Wiz Research found malicious repos could auto-load MCP servers from .amazonq/mcp.json without consent, executing code with full AWS credential inheritance. Patched in Language Servers for AWS 1.69.0; public disclosure June 23–26, 2026 after responsible disclosure starting April 20.

PreScreening Notes

Score: 9/10 — critical priority

Critical supply-chain-style vulnerability in a widely deployed AWS developer tool: malicious MCP configs can inherit full AWS credentials without user consent. Official AWS security bulletin plus Wiz Research validation; patched but disclosure is fresh (June 23–26). Strong software/AI fit for developer audience; no duplicate in pipeline. High-impact security story warrants immediate evaluation.

Evaluation Report

News Value Assessment

DimensionRatingNotes
Timeliness★★★★★Public disclosure June 23–26, 2026; patch available since May 12
Impact★★★★★Full AWS credential theft via malicious repo clone — supply-chain attack vector
Prominence★★★★★AWS official bulletin + Wiz Research; affects VS Code, JetBrains, Eclipse, Visual Studio
Proximity★★★★★Turkish devs using Amazon Q / AWS Toolkit — immediate patch verification needed
Novelty★★★★★MCP auto-execution without consent — new attack class for AI coding assistants

Audience Fit

Critical for software developers using AWS ecosystem and AI coding tools. Directly connects MCP security concerns raised across the agentic AI stack. Pairs naturally with Langflow CVE as “AI tool security week” cluster.

Risk & Ethics Assessment

Verified via AWS Security Bulletin 2026-047, Wiz Research blog, and multiple independent security outlets. Fix deployed May 12 in language server 1.65.0 (CVE-2026-12957) and 1.69.0 (both CVEs). Responsible disclosure timeline clear (April 20 report → May 12 fix → June 23 public). No misinformation concerns.

Publication Strategy

Suggested Angle

Türkçe açı: Amazon Q’da MCP tuzağı — kötü niyetli repo ile AWS credential çalma nasıl mümkün oldu?

Geliştirici güvenlik analizi: .amazonq/mcp.json auto-execution attack chain, environment inheritance ile credential exfiltration, CVE-2026-12957/12958 farkları. Patch durumu (Language Servers ≥1.69.0) ve Türk ekipler için kontrol listesi. MCP güvenliği tartışmasına bağlam — agentic AI stack’in yeni saldırı yüzeyi.

Source Analysis

Research Notes

Additional Sources Found

Key Facts Verified

  • Confirmed: CVE-2026-12957 auto-executes .amazonq/mcp.json without consent; full environment inheritance enables AWS credential exfiltration
  • Confirmed: CVE-2026-12958 symlink validation gap fixed only in Language Server 1.69.0
  • Confirmed: Disclosure timeline — April 20 report → May 12 fix → June 23–26 public
  • Verified: Part of systemic MCP auto-execution pattern (Claude Code, Cursor, Windsurf CVEs per Wiz)

Broader Context

June 2026 “AI security week” cluster with langflow RCE and dirtyclone kernel LPE. Highlights need for MCP consent prompts, workspace trust integration, and minimum environment inheritance for spawned processes.

amazon-q-developer, wiz, mcp, model-context-protocol, ai-agent-security, supply-chain-security, ai-coding-tools, coding-agents, amazon, agentic-coding-infrastructure

Draft Article

Published: 2026-06-26-amazon-q-developer-cve-2026-12957-mcp

Amazon Q’da MCP Tuzağı: Kötü Niyetli Repo ile AWS Credential Çalma

Editorial Notes

Onaylanan açı ve format: standard (600–800 kelime) — MCP supply-chain saldırı analizi; attack chain açıklaması gerekli.

Reporting agent talimatları:

  • .amazonq/mcp.json auto-execution attack chain’i adım adım açıkla (diagram veya numaralı liste)
  • CVE-2026-12957 vs CVE-2026-12958 farklarını netleştir (1.69.0 her ikisi için gerekli)
  • Responsible disclosure timeline: Nisan 20 → Mayıs 12 patch → Haziran 23-26 public
  • Türk ekipler için patch doğrulama checklist’i ekle
  • Wiz’in sistemik MCP pattern bulgusuna (Claude Code, Cursor, Windsurf) kısa atıf

Başlık önerileri:

  • Amazon Q’da MCP tuzağı: Kötü niyetli repo ile AWS credential çalma
  • CVE-2026-12957: Amazon Q Developer’da onaysız MCP auto-execution açığı
  • AI coding assistant’larda yeni saldırı vektörü: MCP config ile credential theft

Makalede mutlaka yer alması gerekenler:

  • AWS Security Bulletin 2026-047 resmi kaynak
  • Full AWS credential inheritance via environment
  • Language Servers for AWS ≥1.69.0 patch gereksinimi
  • VS Code, JetBrains, Eclipse, Visual Studio etkilenen IDE’ler
  • MCP consent prompt eksikliği tartışması
  • Güvenlik kümesi: DirtyClone LPE ile birlikte “Haziran AI güvenlik haftası” bağlamı