High severity7.8NVD Advisory· Published Jun 23, 2026· Updated Jun 23, 2026
CVE-2026-12958
CVE-2026-12958
Description
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.
To remediate this issue, users should upgrade to version 1.69.0 or higher.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=1.69.0
Patches
Vulnerability mechanics
References
2News mentions
7- AI Coding Tools Can Fake Approval PromptsGovInfoSecurity · Jul 10, 2026
- New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI AgentsCyber Security News · Jul 9, 2026
- GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding AgentsThe Hacker News · Jul 9, 2026
- Bug in top AI coding agents shows that Unix-era security headaches never really dieThe Register Security · Jul 8, 2026
- Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud EnvironmentsCyber Security News · Jun 26, 2026
- Amazon Q Flaw Enabled Cloud Credential Theft via Malicious RepositoriesSecurityWeek · Jun 26, 2026
- Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP ConfigsThe Hacker News · Jun 26, 2026