{"data":{"id":"ef704bee-7e72-4186-9574-f0d308e1503b","title":"GHSA-6v3r-4p5c-mrp5: Language Servers for AWS vulnerable to arbitrary file write","summary":"Language Servers for AWS (developer tools used in IDEs like VS Code and JetBrains) has a vulnerability where it fails to validate symlinks (shortcuts that point to files elsewhere on the system). An attacker could create a malicious workspace containing a symlink that points outside the workspace boundary, causing the tool to write files to unauthorized locations without asking the user first.","solution":"Upgrade to AWS Language Servers version 1.69.0 or later. The source states: 'This issue has been addressed in AWS Language Servers version 1.69.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.'","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-6v3r-4p5c-mrp5","publishedAt":"2026-09-24T19:15:39.000Z","cveId":"CVE-2026-12958","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":[],"issueType":"vulnerability","affectedPackages":["@aws/lsp-codewhisperer@< 0.0.117 (fixed: 0.0.117)"],"affectedVendors":["Amazon"],"affectedVendorsRaw":["AWS","Amazon Q Developer","Language Servers for AWS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00191,"patchAvailable":true,"disclosureDate":"2026-09-24T19:15:39.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}