CVE-2026-12957: Arbitrary Code Execution in Language Servers for AWS
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.
To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Language Servers for AWSto a version that resolves this vulnerability.Fixed in 1.65.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12957?
The severity of CVE-2026-12957 is high, rated at 8.5.
How do I fix CVE-2026-12957?
To fix CVE-2026-12957, update the Language Servers for AWS to version 1.65.0 or later.
What kind of vulnerability is CVE-2026-12957?
CVE-2026-12957 is an arbitrary code execution vulnerability due to improper trust boundary enforcement.
What platforms are affected by CVE-2026-12957?
CVE-2026-12957 affects all supported platforms running Language Servers for AWS prior to version 1.65.0.
What happens if I exploit CVE-2026-12957?
Exploiting CVE-2026-12957 allows an attacker to execute arbitrary commands through malicious project configuration files.