Opening SecureFlowAmazon Q MCP Auto-Execution to Cloud Credential Theft
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Wiz aidefend-sf0011

Amazon Q MCP Auto-Execution to Cloud Credential Theft

  • Autonomous Agents
  • Tool Integrations & MCP
  • System Compromise & RCE
  • Credential & Identity Theft

Wiz disclosed CVE-2026-12957 in Amazon Q Developer for VS Code, where workspace MCP configuration could be auto-loaded without consent, start command-backed MCP servers, inherit developer environment variables, and exfiltrate AWS identity data before AWS fixed the issue in language server 1.65.0.

Mapped threat techniques

Source