Alerts
Amazon Q Developer Flaw (CVE-2026-12957) Lets Malicious Repos Steal AWS Credentials
A high-severity flaw in Amazon Q Developer (CVE-2026-12957, CVSS 8.5) let a single config file in a cloned repo run commands and steal live AWS credentials. Amazon patched it in Language Servers for AWS 1.65.0. Update to 1.69.0.