Researchers warn many AI coding assistants now execute commands from project configurations

Amazon patched CVE-2026-12957, a high-severity Amazon Q Developer flaw that let malicious MCP config run commands and steal AWS credentials.

A high-severity flaw in Amazon Q Developer let a cloned repo silently run an MCP server that stole AWS credentials. Wiz found it, Amazon patched it.