How Malicious MCP Configs in Amazon Q Developer Could Execute Arbitrary Code — and How to Stop It
A flaw in Amazon Q Developer allowed malicious repositories to inject rogue Model Context Protocol (MCP) configurations, leading to arbitrary code execution. The vulnerability exploited the agent's tr…