A high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code allowed attackers to execute arbitrary code on a developer's workstation. The flaw, tracked as CVE-2026-12957, stemmed from the automatic loading of Model Context Protocol (MCP) configurations found within a repository's hidden directory. When a developer...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!