Code Execution Vulnerability in WSO2 Integrator MI VS Code Extension
CVE-2026-19515

7HIGH

Key Information:

Vendor

Wso2

Vendor
CVE Published:
15 September 2026

What is CVE-2026-19515?

The WSO2 Integrator MI VS Code extension contains a vulnerability that arises from improper sanitization and validation of user input. When processing Micro Integrator projects sourced from untrusted origins, a malicious project can exploit this flaw to inject and execute arbitrary operating system commands via the unit test execution process. Successful exploitation hinges on the user granting workspace trust to the compromised project and subsequently executing the unit tests, potentially allowing attackers to manipulate the system based on the user account’s privileges.

Affected Version(s)

WSO2 Integrator: MI for Visual Studio Code 0 <= 4.1.3

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mykhailo Kholiev
.