Amazon Q Ran MCP Commands Supplied by Project Repositories
CVE-2026-12957 allowed project configuration to start MCP processes with a developer's environment. AWS fixed the flaw in Language Servers for AWS 1.65.0.
Read article →Reader view
Choose the default article length.
Software vulnerabilities, dependencies, and application security.
CVE-2026-12957 allowed project configuration to start MCP processes with a developer's environment. AWS fixed the flaw in Language Servers for AWS 1.65.0.
Read article →Island found more than 800 fake skills and MCP servers using credible READMEs and ZIP files to turn capability searches into malware installs.
Read article →Five poisoned releases avoided install hooks, launching a detached Node.js process when developer or CI tooling loaded the affected module.
Read article →Cursor 3.0 fixed path-handling failures that let injected instructions write beyond a project and tamper with the sandbox protecting the host.
Read article →A routine page fetch in older Kiro builds could end with attacker-controlled code running through a rewritten MCP configuration.
Read article →