In plain language
What this advisory means
Two security issues (CVE-2026-12957 and CVE-2026-12958) were found in the Language Servers used by Amazon Q Developer's IDE plugins. These issues could let a local user execute commands or access files outside of trusted project areas if they open a malicious workspace and accept the trust prompt. AWS fixed these by releasing Language Servers version 1.69.0 and updated plugins bundling that version. Users should upgrade their Amazon Q Developer IDE plugins to apply the fix. No workarounds are available.
Technical explanation
How the issue affects the environment
CVE-2026-12957 describes improper trust boundary enforcement in Language Servers for AWS prior to version 1.65.0. When a local user opens a maliciously crafted workspace and accepts the trust prompt, commands in project configuration files may be executed automatically. CVE-2026-12958 describes missing symbolic link validation in Language Servers for AWS prior to version 1.69.0. A maliciously crafted symlink in a workspace could resolve to file paths outside the workspace trust boundary, potentially exposing unauthorized files. Both vulnerabilities affect the Amazon Q Developer IDE plugins for Visual Studio Code, JetBrains, Eclipse, and Visual Studio that bundle the Language Servers. These issues are remediated in Language Servers for AWS version 1.69.0 and corresponding updated plugins.
Operational impact
Why teams should care
If exploited, these issues could allow a local user to run unintended commands or access files beyond the intended trust boundaries in development environments. This could compromise developer workstation security, potentially leading to code manipulation or exposure of sensitive data. Organizations using Amazon Q Developer IDE plugins should upgrade promptly to reduce risk of exploitation.
Immediate action
Upgrade Language Servers for AWS to version 1.69.0 or later. Also upgrade all Amazon Q Developer IDE plugins to versions that bundle Language Servers 1.69.0 or newer. Ensure any forked or derivative code incorporates these fixes.
Affected and fixed releases
Temporary risk reduction
No workarounds are available.
Evidence and validation checklist
- AWS Security Bulletin 2026-047-AWS detailing both CVE-2026-12957 and CVE-2026-12958
- Vendor statement about affected products and fixed version 1.69.0
- Acknowledgement of coordinated disclosure process involving security partner Wiz
- Clear description of vulnerability mechanisms and required user action (trust workspace)
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
