CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins
Bulletin ID: 2026-047-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 06/23/2026 09:00 AM PDT
Description:
Language Servers for AWS provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and Visual Studio).
We identified CVE-2026-12957, an improper trust boundary enforcement issue in Language Servers for AWS before version 1.65.0. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.
We identified CVE-2026-12958, a missing symlink-validation issue in Language Servers for AWS before version 1.69.0. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.
These issues affect the Amazon Q Developer IDE plugins, which bundle Language Servers for AWS. Both issues are remediated in Language Servers for AWS version 1.69.0.
Affected products & versions:
- Language Servers for AWS: < 1.69.0
- Amazon Q Developer for Visual Studio Code: < 2.20
- Amazon Q Developer for JetBains: < 4.3
- Amazon Q Developer for Eclipse: < 2.7.4
- AWS Toolkit with Amazon Q for Visual Studio: < 1.94.0.0
Resolution:
These issues have been addressed in Language Servers for AWS version 1.69.0 and the corresponding Amazon Q Developer plugin releases that bundle it. We recommend upgrading to the latest version of your Amazon Q Developer IDE plugin, and ensuring any forked or derivative code is patched to incorporate the new fixes.
- Amazon Q Developer for VS Code
- Amazon Q Developer for JetBrains
- Amazon Q Developer for Eclipse
- Amazon Q Developer for Visual Studio
Workarounds:
No workarounds are available.
References:
Acknowledgement:
We would like to thank Wiz for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.