High severity7.8NVD Advisory· Published Jun 23, 2026· Updated Jun 23, 2026
CVE-2026-12957
CVE-2026-12957
Description
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.
To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.65.0
Patches
Vulnerability mechanics
References
2News mentions
7- GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding AgentsThe Hacker News · Jul 9, 2026
- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News · Jun 29, 2026
- Amazon Q VS Extension Flaw Leads to Cloud Credential TheftDark Reading · Jun 29, 2026
- Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud EnvironmentsCyber Security News · Jun 26, 2026
- Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud credsThe Register Security · Jun 26, 2026
- Amazon Q Flaw Enabled Cloud Credential Theft via Malicious RepositoriesSecurityWeek · Jun 26, 2026
- Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP ConfigsThe Hacker News · Jun 26, 2026