CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins

Bulletin ID: 2026-047-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 06/23/2026 09:00 AM PDT

Language Servers for AWS provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and Visual Studio).

We identified CVE-2026-12957, an improper trust boundary enforcement issue in Language Servers for AWS before version 1.65.0. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.

We identified CVE-2026-12958, a missing symlink-validation issue in Language Servers for AWS before version 1.69.0. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.

These issues affect the Amazon Q Developer IDE plugins, which bundle Language Servers for AWS. Both issues are remediated in Language Servers for AWS version 1.69.0.

  • Amazon Q Developer for Visual Studio Code: < 2.20
  • AWS Toolkit with Amazon Q for Visual Studio: < 1.94.0.0
  • These issues have been addressed in Language Servers for AWS version 1.69.0 and the corresponding Amazon Q Developer plugin releases that bundle it. We recommend upgrading to the latest version of your Amazon Q Developer IDE plugin, and ensuring any forked or derivative code is patched to incorporate the new fixes.

    We would like to thank Wiz for collaborating on this issue through the coordinated vulnerability disclosure process.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-047-aws/

    Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Amazon Web Services — imported from official source
    Official source
    https://aws.amazon.com/security/security-bulletins/feed/ RSS
    Imported
    September 29, 2026 16:00
    Versions
    1 recorded
    Identity
    d33a216474b1f059f63b09ec5274d2b7cec37b56

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.