1.
Wiz Research found that the Amazon Q VS Code extension auto-loaded MCP servers from workspace files, letting a malicious repo run code and steal cloud credentials via a git clone (CVE-2026-12957).
Skip to content
Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-12957.