June 26, 2026

A single config file in a cloned repository could steal your AWS credentials through Amazon Q Developer

a computer screen with a lot of text on it
Markus Spiske / Unsplash

A high-severity flaw in Amazon Q Developer allowed a malicious code repository to silently execute commands on a developer’s machine and steal their AWS credentials. Wiz Research discovered the vulnerability, tracked as CVE-2026-12957, and reported i...