Command Injection Vulnerability in Spring CLI VSCode Extension
CVE-2026-22718
6.8MEDIUM
What is CVE-2026-22718?
The Spring CLI extension for Visual Studio Code is susceptible to a command injection vulnerability, which could allow an attacker to execute arbitrary commands on the user's machine. This issue may compromise the integrity and security of the system by enabling unauthorized command execution, emphasizing the importance of applying security updates and mitigating risks associated with this flaw.
Affected Version(s)
CLI VSCode Extension 0.9.0 and older
