Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Two security issues (CVE-2026-12957 and CVE-2026-12958) were found in the Language Servers used by Amazon Q Developer's IDE plugins. These issues could let a local user execute commands or access files outside of trusted project areas if they open a malicious workspace and accept the trust prompt. AWS fixed these by releasing Language Servers version 1.69.0 and updated plugins bundling that version. Users should upgrade their Amazon Q Developer IDE plugins to apply the fix. No workarounds are available.

QCS published 10/10/2026, 8:51:56 am ISTVendor disclosure 9/10/2026, 11:49:17 pm ISTVerified 11/10/2026, 3:31:22 am ISTRevision 1

In plain language

What this advisory means

Two security issues (CVE-2026-12957 and CVE-2026-12958) were found in the Language Servers used by Amazon Q Developer's IDE plugins. These issues could let a local user execute commands or access files outside of trusted project areas if they open a malicious workspace and accept the trust prompt. AWS fixed these by releasing Language Servers version 1.69.0 and updated plugins bundling that version. Users should upgrade their Amazon Q Developer IDE plugins to apply the fix. No workarounds are available.

Technical explanation

How the issue affects the environment

CVE-2026-12957 describes improper trust boundary enforcement in Language Servers for AWS prior to version 1.65.0. When a local user opens a maliciously crafted workspace and accepts the trust prompt, commands in project configuration files may be executed automatically. CVE-2026-12958 describes missing symbolic link validation in Language Servers for AWS prior to version 1.69.0. A maliciously crafted symlink in a workspace could resolve to file paths outside the workspace trust boundary, potentially exposing unauthorized files. Both vulnerabilities affect the Amazon Q Developer IDE plugins for Visual Studio Code, JetBrains, Eclipse, and Visual Studio that bundle the Language Servers. These issues are remediated in Language Servers for AWS version 1.69.0 and corresponding updated plugins.

Operational impact

Why teams should care

If exploited, these issues could allow a local user to run unintended commands or access files beyond the intended trust boundaries in development environments. This could compromise developer workstation security, potentially leading to code manipulation or exposure of sensitive data. Organizations using Amazon Q Developer IDE plugins should upgrade promptly to reduce risk of exploitation.

Immediate action

Upgrade Language Servers for AWS to version 1.69.0 or later. Also upgrade all Amazon Q Developer IDE plugins to versions that bundle Language Servers 1.69.0 or newer. Ensure any forked or derivative code incorporates these fixes.

Affected and fixed releases

Affected versionsLanguage Servers for AWS before 1.65.0 (CVE-2026-12957), Language Servers for AWS before 1.69.0 (CVE-2026-12958)
Fixed versionsLanguage Servers for AWS version 1.69.0

Temporary risk reduction

No workarounds are available.

Evidence and validation checklist

  • AWS Security Bulletin 2026-047-AWS detailing both CVE-2026-12957 and CVE-2026-12958
  • Vendor statement about affected products and fixed version 1.69.0
  • Acknowledgement of coordinated disclosure process involving security partner Wiz
  • Clear description of vulnerability mechanisms and required user action (trust workspace)

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source