June 26, 2026
Amazon Q MCP flaw (CVE-2026-12957) enabled cloud credential theft by opening a malicious repo
Wiz Research disclosed a high-severity vulnerability (CVSS 8.5) in Amazon Q Developer: the AI coding tool auto-loaded MCP configurations from workspace directories without user consent, meaning a developer who simply opened a malicious Git repository could trigger arbitrary code execution and cloud credential exfiltration silently. A single malicious .amazonq/mcp.json file was sufficient to pipe AWS credentials to an attacker-controlled server with zero user interaction. Amazon patched the flaw on May 12, 2026; public disclosure followed on June 26.
MCP servers are rapidly becoming a primary lateral movement surface in developer environments. Salt's agentic API monitoring covers the API calls MCP-enabled tools make on behalf of developers, flagging anomalous outbound data flows and unauthorized credential-adjacent API activity before exfiltration completes.
Agentic/MCP
Read full story