Amazon Q Developer Amazon Q Developer is a product from Amazon Web Services. Affiliate programs may be available through the AWS Partner Network. CybersecurityBoard may earn a commission if you use this link.
Visit product / provider
A vulnerability in Windsurf allowed attacker-controlled content to rewrite local MCP config and register a malicious server, leading to command execution.
Discovered from: Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
Amazon Q Developer Amazon Q Developer is a product from Amazon Web Services. Affiliate programs may be available through the AWS Partner Network. CybersecurityBoard may earn a commission if you use this link.
Visit product / provider
Amazon Q Developer Amazon Q Developer is a product from Amazon Web Services. Affiliate programs may be available through the AWS Partner Network. CybersecurityBoard may earn a commission if you use this link.
Visit product / provider