Affected Systems
Amazon Q Developer (all versions prior to patch). Affects developers using the IDE plugin who clone or open malicious repositories containing crafted Model Context Protocol (MCP) server configurations.
Exploitation Status
Patch available from Amazon. No public information on active exploitation or proof-of-concept availability at this time.
Business Impact
Developers using Amazon Q Developer are at risk of arbitrary command execution and cloud credential theft when interacting with untrusted repositories. Successful exploitation could lead to AWS account compromise, lateral movement, and supply chain attacks. Organizations with developers using Amazon Q should prioritize patching to prevent credential exposure and unauthorized cloud access.
Urgency
🟠Within 24 hours
Recommended Actions
- Update Amazon Q Developer IDE plugin to the latest patched version immediately across all developer workstations
- Audit recent repository clones and MCP server interactions for suspicious activity in Amazon Q logs
- Rotate AWS credentials for developers who used vulnerable Amazon Q versions with untrusted repositories
- Implement repository vetting procedures and restrict developers from cloning unverified third-party repositories
- Monitor AWS CloudTrail logs for anomalous API calls from developer IAM credentials in the past 30 days
