HIGH GitHub

CVE-2026-12957

Language Servers for AWS Vulnerable to Arbitrary Code Execution

### Summary Language Servers for AWS (the aws/language-servers project) provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and Visual Studio). Improper trust boundary enforcement in Language Servers for AWS may allow for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed.

Affected Products

References

Published: 2026-09-24 · Source: GitHub · Feed updated: 2026-09-24
This high severity vulnerability was published on 2026-09-24 via GitHub. Affected: npm/@aws/lsp-codewhisperer < 0.0.113.
vulnfeed aggregates 11711 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.