Code Execution Vulnerability in WSO2 Integrator MI VS Code Extension
CVE-2026-19515
7HIGH
Key Information:
- Vendor
Wso2
- Vendor
- CVE Published:
- 15 September 2026
What is CVE-2026-19515?
The WSO2 Integrator MI VS Code extension contains a vulnerability that arises from improper sanitization and validation of user input. When processing Micro Integrator projects sourced from untrusted origins, a malicious project can exploit this flaw to inject and execute arbitrary operating system commands via the unit test execution process. Successful exploitation hinges on the user granting workspace trust to the compromised project and subsequently executing the unit tests, potentially allowing attackers to manipulate the system based on the user account’s privileges.
Affected Version(s)
WSO2 Integrator: MI for Visual Studio Code 0 <= 4.1.3
