Command Injection Vulnerability in Visual Studio Code Ansible Lightspeed Extension
CVE-2026-44191
7.8HIGH
What is CVE-2026-44191?
A command injection vulnerability has been identified in the Visual Studio Code Ansible Lightspeed extension. This flaw arises from insufficient validation of settings related to the execution environment, specifically the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts. Attackers can exploit this weakness to inject shell separators, leading to remote code execution on the victim's system. This exploit can occur automatically during Language Server initialization or can be triggered manually during playbook execution, enabling potential full system compromise while operating under the privileges of the Visual Studio Code user.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Laura Pardo (Red Hat Inc.).