Summary
AWS disclosed CVE-2026-12957 and CVE-2026-12958 (Bulletin 2026-047) affecting Amazon Q Developer IDE plugins. Wiz Research found malicious repos could auto-load MCP servers from .amazonq/mcp.json without consent, executing code with full AWS credential inheritance. Patched in Language Servers for AWS 1.69.0; public disclosure June 23–26, 2026 after responsible disclosure starting April 20.
PreScreening Notes
Score: 9/10 — critical priority
Critical supply-chain-style vulnerability in a widely deployed AWS developer tool: malicious MCP configs can inherit full AWS credentials without user consent. Official AWS security bulletin plus Wiz Research validation; patched but disclosure is fresh (June 23–26). Strong software/AI fit for developer audience; no duplicate in pipeline. High-impact security story warrants immediate evaluation.
Evaluation Report
News Value Assessment
| Dimension | Rating | Notes |
|---|---|---|
| Timeliness | ★★★★★ | Public disclosure June 23–26, 2026; patch available since May 12 |
| Impact | ★★★★★ | Full AWS credential theft via malicious repo clone — supply-chain attack vector |
| Prominence | ★★★★★ | AWS official bulletin + Wiz Research; affects VS Code, JetBrains, Eclipse, Visual Studio |
| Proximity | ★★★★★ | Turkish devs using Amazon Q / AWS Toolkit — immediate patch verification needed |
| Novelty | ★★★★★ | MCP auto-execution without consent — new attack class for AI coding assistants |
Audience Fit
Critical for software developers using AWS ecosystem and AI coding tools. Directly connects MCP security concerns raised across the agentic AI stack. Pairs naturally with Langflow CVE as “AI tool security week” cluster.
Risk & Ethics Assessment
Verified via AWS Security Bulletin 2026-047, Wiz Research blog, and multiple independent security outlets. Fix deployed May 12 in language server 1.65.0 (CVE-2026-12957) and 1.69.0 (both CVEs). Responsible disclosure timeline clear (April 20 report → May 12 fix → June 23 public). No misinformation concerns.
Publication Strategy
- Format:
standard(600–800 words) — attack chain deserves explanation beyond brief advisory - Related wiki: ai-coding-tools, supply-chain-security, amazon
Suggested Angle
Türkçe açı: Amazon Q’da MCP tuzağı — kötü niyetli repo ile AWS credential çalma nasıl mümkün oldu?
Geliştirici güvenlik analizi: .amazonq/mcp.json auto-execution attack chain, environment inheritance ile credential exfiltration, CVE-2026-12957/12958 farkları. Patch durumu (Language Servers ≥1.69.0) ve Türk ekipler için kontrol listesi. MCP güvenliği tartışmasına bağlam — agentic AI stack’in yeni saldırı yüzeyi.
Source Analysis
Research Notes
Additional Sources Found
- 2026-06-26-amazon-q-wiz-research-blog — primary technical analysis, PoC, disclosure timeline
- 2026-06-26-amazon-q-aws-bulletin-047 — official affected versions and remediation
- 2026-06-26-amazon-q-heal-security-analysis — independent security outlet corroboration
Key Facts Verified
- Confirmed: CVE-2026-12957 auto-executes
.amazonq/mcp.jsonwithout consent; full environment inheritance enables AWS credential exfiltration - Confirmed: CVE-2026-12958 symlink validation gap fixed only in Language Server 1.69.0
- Confirmed: Disclosure timeline — April 20 report → May 12 fix → June 23–26 public
- Verified: Part of systemic MCP auto-execution pattern (Claude Code, Cursor, Windsurf CVEs per Wiz)
Broader Context
June 2026 “AI security week” cluster with langflow RCE and dirtyclone kernel LPE. Highlights need for MCP consent prompts, workspace trust integration, and minimum environment inheritance for spawned processes.
Related Wiki Pages
amazon-q-developer, wiz, mcp, model-context-protocol, ai-agent-security, supply-chain-security, ai-coding-tools, coding-agents, amazon, agentic-coding-infrastructure
Draft Article
Published: 2026-06-26-amazon-q-developer-cve-2026-12957-mcp
Amazon Q’da MCP Tuzağı: Kötü Niyetli Repo ile AWS Credential Çalma
Editorial Notes
Onaylanan açı ve format: standard (600–800 kelime) — MCP supply-chain saldırı analizi; attack chain açıklaması gerekli.
Reporting agent talimatları:
.amazonq/mcp.jsonauto-execution attack chain’i adım adım açıkla (diagram veya numaralı liste)- CVE-2026-12957 vs CVE-2026-12958 farklarını netleştir (1.69.0 her ikisi için gerekli)
- Responsible disclosure timeline: Nisan 20 → Mayıs 12 patch → Haziran 23-26 public
- Türk ekipler için patch doğrulama checklist’i ekle
- Wiz’in sistemik MCP pattern bulgusuna (Claude Code, Cursor, Windsurf) kısa atıf
Başlık önerileri:
- Amazon Q’da MCP tuzağı: Kötü niyetli repo ile AWS credential çalma
- CVE-2026-12957: Amazon Q Developer’da onaysız MCP auto-execution açığı
- AI coding assistant’larda yeni saldırı vektörü: MCP config ile credential theft
Makalede mutlaka yer alması gerekenler:
- AWS Security Bulletin 2026-047 resmi kaynak
- Full AWS credential inheritance via environment
- Language Servers for AWS ≥1.69.0 patch gereksinimi
- VS Code, JetBrains, Eclipse, Visual Studio etkilenen IDE’ler
- MCP consent prompt eksikliği tartışması
- Güvenlik kümesi: DirtyClone LPE ile birlikte “Haziran AI güvenlik haftası” bağlamı