{"data":{"id":"fa6c56f7-4fc5-46d8-b213-8bd5772eb457","title":"GHSA-xhcr-j4j9-3gh7: Language Servers for AWS Vulnerable to Arbitrary Code Execution","summary":"Language Servers for AWS (software that helps Amazon Q Developer provide AI coding assistance in IDEs like Visual Studio Code and JetBrains) has a security flaw where improper trust boundary enforcement (failing to properly verify what code should be trusted) allows arbitrary code execution (running any commands an attacker wants). If a user opens a malicious workspace and trusts it when prompted, commands hidden in the project configuration files will automatically run on their computer.","solution":"Upgrade to Language Servers for AWS version 1.65.0 or later. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-xhcr-j4j9-3gh7","publishedAt":"2026-09-24T19:13:53.000Z","cveId":"CVE-2026-12957","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["@aws/lsp-codewhisperer@< 0.0.113 (fixed: 0.0.113)"],"affectedVendors":["Amazon"],"affectedVendorsRaw":["Amazon Q Developer","Language Servers for AWS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00178,"patchAvailable":true,"disclosureDate":"2026-09-24T19:13:53.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}