[CVE-2026-12957] MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension
wiz.io | blog | CVE-2026-12957 | #cloud | #vulnerability-research | #credential-theft | #mcp | #ai-coding-assistants | #vscode-extension | #amazon-q | #cve-2026-12957
Summary
Wiz Research found that the Amazon Q VS Code extension auto-loaded MCP servers from workspace files, letting a malicious repo run code and steal cloud credentials via a git clone (CVE-2026-12957).
- Published
- Collected
Skip to content