GHSA-xhcr-j4j9-3gh7: Language Servers for AWS Vulnerable to Arbitrary Code Execution
Summary
Language Servers for AWS (software that helps Amazon Q Developer provide AI coding assistance in IDEs like Visual Studio Code and JetBrains) has a security flaw where improper trust boundary enforcement (failing to properly verify what code should be trusted) allows arbitrary code execution (running any commands an attacker wants). If a user opens a malicious workspace and trusts it when prompted, commands hidden in the project configuration files will automatically run on their computer.
Solution / Mitigation
Upgrade to Language Servers for AWS version 1.65.0 or later. AWS recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Vulnerability Details
EPSS: 0.2%
Yes
September 24, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://github.com/advisories/GHSA-xhcr-j4j9-3gh7
First tracked: September 24, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%