CVE 8.5 HIGH

Arbitrary Code Execution in Language Servers for AWS_CVE-2026-12957

8.5 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.



To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.

AI Analysis

Arbitrary code execution vulnerability in Language Servers for AWS due to improper trust boundary enforcement

Basic Information

ID CVE-2026-12957
Source AMZN
Published Jun 23, 2026 at 16:02
Modified Jun 23, 2026 at 17:50

Affected Product

Vendor Amazon Web Services
Product Language Servers for AWS
Affected Versions Amazon Web Services Language Servers for AWS 0

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor Amazon Web Services
Product Language Servers for AWS
Version before 1.65.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.