Local Access Vulnerability in Ansible Lightspeed for Visual Studio Code
CVE-2026-44187

3.3LOW

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
22 July 2026

What is CVE-2026-44187?

A vulnerability has been identified in the Ansible Lightspeed extension for Visual Studio Code that allows local attackers or malware running with the user's privileges to access sensitive information. The flaw resides in the way the extension handles the Google Gemini API key, which is stored in plain text within the user's configuration files and is written to output log files. This insecure storage method poses a risk of information disclosure, enabling unauthorized parties to retrieve API credentials, potentially leading to unauthorized consumption of the user's API quota.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laura Pardo (Red Hat Inc.).
.