Command Injection Flaw in Visual Studio Code Ansible Lightspeed Extension by Red Hat
CVE-2026-44189

7.8HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
22 July 2026

What is CVE-2026-44189?

A vulnerability exists in the Ansible Lightspeed extension for Visual Studio Code that allows a command injection attack via improperly sanitized playbook filenames. An attacker can leverage this flaw by including special characters in the filename. When the user executes the compromised playbook, it prompts the execution of arbitrary code with the user's privileges. The ramifications of this vulnerability can lead to severe consequences, such as full system compromise, exfiltration of sensitive data, unauthorized modification of project files, and potential permanent data loss.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laura Pardo (Red Hat Inc.).
.