AWS Security Bulletin 2026-047-AWS (published June 23, 2026):
CVE-2026-12957: Improper trust boundary enforcement in Language Servers for AWS before 1.65.0. Malicious workspace config files may auto-execute commands when user trusts workspace.
CVE-2026-12958: Missing symlink validation before 1.69.0. Malicious symlinks may resolve outside workspace trust boundary.
Both remediated in Language Servers for AWS 1.69.0. Affected plugins: Amazon Q Developer for VS Code <2.20, JetBrains <4.3, Eclipse <2.7.4, AWS Toolkit with Amazon Q for Visual Studio <1.94.0.0.
Recommendation: upgrade to latest Amazon Q Developer IDE plugin. Language server auto-updates unless blocked by network policy.