Wiz Research disclosed a high-severity flaw (CVE-2026-12957) in Amazon Q Developer, Amazon’s AI coding assistant, which automatically read and executed MCP server configuration files from an opened project without any prompt or consent check. A developer who cloned and opened a repository containing a malicious configuration could have arbitrary code executed and cloud credentials exposed. Amazon patched the issue, along with a related flaw (CVE-2026-12958), in version 1.69.0; no in-the-wild exploitation was reported.