CVE-2026-12957 Details
Description
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted. To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.
A vulnerability exists in Language Servers for AWS prior to version 1.65.0, across all supported platforms, due to improper trust boundary enforcement. This issue may allow arbitrary code execution. When a local user opens a maliciously crafted workspace and trusts it, any commands within the project's configuration files can be automatically executed.
Users should upgrade to Language Servers for AWS version 1.65.0 or higher. For those using the Amazon Q Developer IDE plugins, the latest versions of these plugins should be installed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-047-aws/ | AMZN | |
| https://github.com/aws/language-servers/security/advisories/GHSA-xhcr-j4j9-3gh7 | AMZN |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | AMZN |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | AMZN |