Crypto Ticker:
sysadmin from 4sysops.com

Amazon Q vulnerability allowed malicious Git repositories to steal cloud credentials

IT News
Friday at 18:15
2 Views
0 Comments
Amazon Q vulnerability allowed malicious Git repositories to steal cloud credentials

A high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code allowed attackers to execute arbitrary code on a developer's workstation. The flaw, tracked as CVE-2026-12957, stemmed from the automatic loading of Model Context Protocol (MCP) configurations found within a repository's hidden directory. When a developer...

Read the full article at the source.

Was this helpful?
Share:

Comments (0)

Please login to post a comment

No comments yet. Be the first to comment!