threat-intel Amazon Q VS Extension Flaw Leads to Cloud Credential Theft A vulnerability in the Amazon Q VS Extension has been discovered, allowing attackers to steal cloud credentials by exploiting the Model Context Protocol (MCP). The flaw stems from the extension’s automatic execution of MCP server configurations without user approval, granting attackers access to sensitive secrets like… Dark Reading · Jun 29, 2026 High CVE-2026-12957CVE-2025-59536CVE-2026-21852aimcpcredentials
threat-intel Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs A critical vulnerability was discovered in Amazon Q Developer, allowing attackers to execute arbitrary code and steal developer credentials by leveraging Model Context Protocol (MCP) configurations within a cloned reposi… The Hacker News · Jun 26, 2026 Critical CVE-2026-12957CVE-2026-12958CVE-2025-59536mcpcloud securitydeveloper credentials