MCP Attacks Hit Developer IDEs: Amazon Q Flaw and Agentjacking

server rack free stock image for MCPwatch editorial use

Wiz discovered CVE-2026-12957 in Amazon Q Developer (CVSS 8.5): opening a repo auto-executes MCP configs, handing cloud credentials to attackers. The same week, Tenet Security disclosed Agentjacking — an 85% success rate attack class using fake Sentry errors to hijack AI coding agents via MCP. Combined with new CVEs in chrome-devtools-mcp and OpenClaw, the developer-tool attack surface for MCP is widening fast.