Command Injection Flaw in Visual Studio Code Ansible Lightspeed Extension by Red Hat
CVE-2026-44189
7.8HIGH
What is CVE-2026-44189?
A vulnerability exists in the Ansible Lightspeed extension for Visual Studio Code that allows a command injection attack via improperly sanitized playbook filenames. An attacker can leverage this flaw by including special characters in the filename. When the user executes the compromised playbook, it prompts the execution of arbitrary code with the user's privileges. The ramifications of this vulnerability can lead to severe consequences, such as full system compromise, exfiltration of sensitive data, unauthorized modification of project files, and potential permanent data loss.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Laura Pardo (Red Hat Inc.).