Command Injection Vulnerability in Visual Studio Code Ansible Lightspeed Extension
CVE-2026-44191

7.8HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
22 July 2026

What is CVE-2026-44191?

A command injection vulnerability has been identified in the Visual Studio Code Ansible Lightspeed extension. This flaw arises from insufficient validation of settings related to the execution environment, specifically the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts. Attackers can exploit this weakness to inject shell separators, leading to remote code execution on the victim's system. This exploit can occur automatically during Language Server initialization or can be triggered manually during playbook execution, enabling potential full system compromise while operating under the privileges of the Visual Studio Code user.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laura Pardo (Red Hat Inc.).
.