Skip to content

security_identifier

CVE-2026-12957

Identifier for a flaw in the Amazon Q Developer extension for Visual Studio Code that loaded MCP server configurations from an opened workspace without a consent or trust check.

Current clusters

build1 publisher

The credential an agent inherits sets the ceiling on the damage

GitGuardian argues that credentials and permissions decide how bad an agent incident gets. Checked against the three 2026 disclosures it cites, the argument holds up, and only one of the three involved steering a model.

Publishers:dev.to

Reality

Evidence60
Adoption45
Hype gap+15
Incentives82
Confidence55