High-severity flaws CVE-2026-12957 and CVE-2026-12958 in Amazon Q Developer Extension for VS Code allowed arbitrary code execution and cloud credential theft when a developer opens a malicious repository.

Root cause: automatic loading of MCP configurations from .amazonq/mcp.json without consent, combined with full environment inheritance including AWS session tokens.

Affected: Language Servers for AWS <1.69.0 and corresponding IDE plugin versions. Patched in 1.69.0. Discovered by Wiz Research, reported April 20, 2026, initial fix May 12, public disclosure June 26 under Bulletin 2026-047-AWS.

Attack scenarios include malicious PRs, typosquatted packages, and fake coding interview repos.