bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Tuesday, June 23, 2026

Critical Security Fixes for Amazon Q Developer Language Servers

Amazon Q Developer IDE plugins (VS Code, JetBrains, Eclipse, Visual Studio) need urgent updates due to two vulnerabilities in Language Servers for AWS. CVE-2026-12957 allows malicious workspace configs to execute commands if you trust the workspace, while CVE-2026-12958 exploits symlink validation gaps. Update to Language Servers for AWS 1.69.0 or your IDE plugin's latest version immediately—user action is required.

> source: aws.amazon.com