A critical security flaw in Amazon Q Developer enabled malicious code repositories to silently execute commands on developers’ machines, potentially stealing AWS credentials. Discovered by Wiz Research and identified as CVE-2026-12957, the vulnerability was reported to Amazon on April 20. Amazon issued a patch on May 12, with the flaw’s details disclosed publicly today.
Back