HIGH GitHub
CVE-2026-12957
Language Servers for AWS Vulnerable to Arbitrary Code Execution
### Summary
Language Servers for AWS (the aws/language-servers project) provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and
Visual Studio).
Improper trust boundary enforcement in Language Servers for AWS may allow for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically
executed.
Affected Products
- npm/@aws/lsp-codewhisperer < 0.0.113
References
- https://github.com/advisories/GHSA-xhcr-j4j9-3gh7
- https://github.com/aws/language-servers/security/advisories/GHSA-xhcr-j4j9-3gh7
- https://nvd.nist.gov/vuln/detail/CVE-2026-12957
- https://github.com/Amazon-Q-Developer/language-servers/pull/2708
This high severity vulnerability was published on 2026-09-24 via GitHub. Affected: npm/@aws/lsp-codewhisperer < 0.0.113.
vulnfeed aggregates 11711 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.