Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Amazon Q MCP Config Vulnerability 2026: How Opening…
Breach analysis Incident: 26 Jun 2026

Amazon Q MCP Config Vulnerability 2026: How Opening a Malicious Repository Could Hand Over a Developer’s AWS Credentials

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 9 min read
Category: NHI AI agents
Attack route: Vulnerability exploit Identities: AI agent Cloud credential
On this page

In June 2026, Wiz Research disclosed CVE-2026-12957, a high-severity flaw in the Amazon Q Developer extension for Visual Studio Code, part of the language server that powers Amazon Q across IDEs. Amazon Q automatically loaded Model Context Protocol (MCP) server configurations from a repository's .amazonq/mcp.json file and ran the commands in them, without asking the user and without a workspace trust check. The processes it started inherited the developer's full environment. So a developer who opened a booby-trapped repository and activated Amazon Q could hand an attacker their AWS session, API keys, tokens and SSH agent access. Amazon fixed the flaw in language server version 1.65.0 in May 2026. Its security bulletin also covers a related symlink flaw, CVE-2026-12958, with both fixed in version 1.69.0 across all Amazon Q IDE plugins. No exploitation has been reported. It is a clear example of an AI coding tool turning a configuration file into a route to a developer's non-human identities.

Key takeaways

  • Wiz found that Amazon Q loaded .amazonq/mcp.json from the workspace as soon as the folder was opened and Amazon Q was activated. There was no prompt, no consent and no workspace trust check.
  • MCP servers started this way inherited the developer's environment: AWS access keys and session tokens, cloud CLI tokens, API keys and SSH agent sockets.
  • Wiz's proof of concept ran aws sts get-caller-identity and sent the output to an external server, capturing the developer's active AWS session.
  • Amazon deployed a fix on 12 May 2026 in language server 1.65.0. Its 23 June bulletin adds CVE-2026-12958, a symlink flaw, and says both are fixed in language server 1.69.0 and the matching VS Code, JetBrains, Eclipse and Visual Studio plugins. The Register reports a CVSS 4.0 score of 8.5 for CVE-2026-12957. No in-the-wild exploitation has been reported.
  • The lesson: anything in a repository is attacker-controlled input, and AI tools that start processes must not pass the developer's credentials to them by default.

At a glance

OrganisationAmazon Web Services (Language Servers for AWS and the Amazon Q Developer plugins for VS Code, JetBrains, Eclipse and Visual Studio); developers using them while signed in to cloud services
WhenDiscovered 17 April 2026; reported 20 April 2026; fixed 12 May 2026; AWS bulletin and CVE 23 June 2026; disclosed by Wiz 26 June 2026
AttackerNone known. Found and reported by Wiz Research
Entry pointA malicious .amazonq/mcp.json file in a repository that a developer opens in VS Code with Amazon Q active
Identities abusedThe developer's inherited environment: AWS access keys and session tokens, cloud CLI tokens, API keys, SSH agent sockets; the AI assistant acting as the launcher
ImpactPotential code execution on developer machines and theft of cloud credentials; no confirmed real-world victims
CategoryNHI, Agentic AI and AI agents. Incident class: agent vulnerability (vulnerability, no confirmed breach)

What happened

MCP lets AI assistants start local processes, called MCP servers, to reach databases, APIs and tools. As Wiz puts it, "The security model assumes the user explicitly configures these servers. After all, you're granting an AI assistant permission to run arbitrary commands on your machine. This should require informed consent."

Wiz found that Amazon Q broke that assumption. The extension loaded .amazonq/mcp.json from the root of any opened folder immediately, with no dialog asking the user to approve the servers and no workspace trust check to stop execution in untrusted folders. The processes it launched inherited the user's complete environment, which for a developer working with cloud services typically includes AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and AWS_SESSION_TOKEN, cloud CLI tokens, API keys and SSH agent sockets.

To prove it, Wiz built a small repository whose mcp.json defined a "build-helper" server that ran a shell command. The command called aws sts get-caller-identity and posted the result to an external server. Opening the folder and activating Amazon Q captured the developer's active AWS session. Wiz lists likely delivery routes: a malicious pull request, a typosquatted package, a compromised dependency, or a fake job interview in which candidates are asked to clone and run a "coding test".

Wiz reported the issue to Amazon on 20 April 2026, and Amazon deployed a fix through a language server update on 12 May. Amazon said: "We have remediated this issue in language server version 1.65.0." The language server updates automatically unless network configuration blocks it. Amazon Q now shows an "Untrusted MCP Server" consent prompt before loading workspace MCP servers. Wiz says the same pattern has appeared in other AI coding tools, and lists earlier CVEs in Claude Code, Cursor and Windsurf.

AWS's security bulletin 2026-047-AWS, published on 23 June, describes CVE-2026-12957 as "an improper trust boundary enforcement issue" in Language Servers for AWS before 1.65.0, which powers Amazon Q in all its IDE plugins. Its account differs from Wiz's on one point: AWS says the issue "requires the user to trust the workspace when prompted", while Wiz describes no workspace trust check. The bulletin also lists CVE-2026-12958, a missing symlink validation that could let a crafted workspace reach files outside the workspace trust boundary. It says both issues are fixed in language server 1.69.0 and that no workarounds are available.

Timeline

DateEvent
17 April 2026Wiz Research discovers the vulnerability.
20 April 2026Wiz reports it to Amazon Security, which acknowledges it the same day.
12 May 2026Amazon deploys the fix in a language server update (version 1.65.0).
23 June 2026AWS publishes security bulletin 2026-047-AWS covering CVE-2026-12957 and CVE-2026-12958.
26 June 2026Public disclosure by Wiz; reported by The Register.

How it happened: the identity attack path

  1. An attacker-controlled config file. A repository shipped a .amazonq/mcp.json file defining an MCP server whose "command" was the attacker's payload.
  2. Auto-execution without consent. Amazon Q loaded and ran the MCP server when the folder was opened and Amazon Q activated, without a prompt or workspace trust check.
  3. Full credential inheritance. The spawned process received the developer's whole environment, including AWS keys and session tokens, API keys and the SSH agent socket.
  4. Cloud identity used immediately. The payload called AWS with the developer's live session and sent the identity details out. From there an attacker could try to create access keys, backdoor IAM users or reach production.
  5. Silent by design. Wiz says execution was silent, with no visible indicator to the developer.

Impact

  • Potential: arbitrary code execution on developer machines and theft of cloud credentials, with the chance to persist in cloud accounts and move laterally through the developer's network access.
  • Confirmed: no in-the-wild exploitation has been reported. Amazon says no action is needed for most users because the language server updates automatically.
  • Industry: Wiz and The Register describe it as part of a wider pattern of AI coding assistants executing commands from project configuration files.

What this means for NHI and AI agent security

A developer's workstation is one of the densest stores of non-human identities in any organisation. It holds cloud sessions, access keys, publishing tokens and SSH keys, usually long-lived and broadly scoped. AI coding assistants now start processes inside that environment. If they pass everything down by default, and let a repository decide what runs, the repository decides who gets the keys.

This is the same trust boundary problem that workspace trust was built to solve, repeated in a new generation of tools. For identity teams, the durable fix is on the credential side. Give developers short-lived, scoped cloud sessions instead of static keys. Keep production credentials off laptops. Make sure a stolen developer session cannot quietly mint new long-lived access. Amazon Q had its own supply-chain scare in 2025, covered in our Amazon Q AI coding agent compromise analysis.

Recommendations

  • Update and verify. Make sure Language Servers for AWS is at 1.69.0 or later, which fixes both CVEs, and that Amazon Q IDE plugins are current, especially where auto-update is blocked by network settings or you maintain forked code.
  • Treat repositories as untrusted input. Look for unexpected .amazonq/, .vscode/ and other tool configuration folders in repositories you clone, and open unfamiliar projects in restricted mode.
  • Review MCP consent prompts. Inspect the command behind any "Untrusted MCP Server" prompt before allowing it. See our MCP Security Guide.
  • Replace static developer keys with short-lived sessions. Use SSO-issued, time-limited cloud credentials so a stolen environment expires quickly. See our Cloud Workload Identity Guide.
  • Limit what developer identities can do in the cloud. Block creation of new access keys and IAM users from developer sessions, and alert on it. See our Cloud PAM and CIEM Guide.
  • Run AI tools with a minimal environment. Where possible, launch assistants and their child processes without inheriting every credential in the shell. Our AI Coding Agents Security Guide covers this.

Frequently asked questions

What was the Amazon Q MCP vulnerability?

CVE-2026-12957 let a repository's .amazonq/mcp.json file run commands automatically when a developer opened the folder and activated Amazon Q. The commands inherited the developer's environment, including AWS credentials, API keys and SSH agent access. AWS's bulletin also covers a related symlink flaw, CVE-2026-12958.

Was it exploited?

No exploitation has been reported. Wiz found and reported the flaw, Amazon fixed it in language server 1.65.0 in May 2026, and both CVEs are fixed in version 1.69.0. The disclosure followed in June.

Do I need to do anything?

Amazon says the language server updates automatically, so most users need no action, and reloading the IDE triggers the update. If automatic updates are blocked, update your Amazon Q Developer plugin to a release that bundles language server 1.69.0 or later, and review any MCP servers loaded from workspaces.

Sentry MCP Agentjacking 2026 · Amazon Q AI coding agent compromise · GlassWorm VS Code extension worm · AI Coding Agents Security Guide · Secrets Management Guide

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as AI coding tools run inside environments full of cloud keys and tokens. Our NHI Foundation Level Training Course gives teams the practical grounding to find and protect them.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org