{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/vscode-extension/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-44190"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ansible Lightspeed Visual Studio Code extension","Visual Studio Code"],"_cs_severities":["high"],"_cs_tags":["command-injection","vscode-extension","remote-code-execution","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Red Hat","Microsoft"],"content_html":"\u003cp\u003eA critical command injection vulnerability, tracked as CVE-2026-44190, has been identified in the Ansible Lightspeed Visual Studio Code extension. This flaw, categorized as CWE-78, enables a remote attacker to execute unauthorized commands on a victim's system. The vulnerability stems from improper validation of user-provided input within the \u003ccode\u003eansible.python.activationScript\u003c/code\u003e setting, which is intended for Python virtual environment activation. Attackers can leverage this by crafting a malicious project; if a user opens or executes such a project, the injected commands will execute with the privileges of the Visual Studio Code application, potentially leading to complete system compromise. The vulnerability affects users of the Ansible Lightspeed extension across various operating systems where VS Code is deployed.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious Visual Studio Code project that contains specially designed input for the \u003ccode\u003eansible.python.activationScript\u003c/code\u003e setting.\u003c/li\u003e\n\u003cli\u003eThe malicious input exploits the command injection vulnerability by embedding unauthorized system commands within the expected virtual environment activation script path.\u003c/li\u003e\n\u003cli\u003eThe attacker convinces a victim to open or execute the specially crafted project within their Visual Studio Code environment.\u003c/li\u003e\n\u003cli\u003eUpon opening the project, the Ansible Lightspeed extension attempts to process the \u003ccode\u003eansible.python.activationScript\u003c/code\u003e setting to activate a Python virtual environment.\u003c/li\u003e\n\u003cli\u003eDue to improper validation, the extension executes the attacker's embedded commands directly on the victim's system.\u003c/li\u003e\n\u003cli\u003eThe executed commands run with the same privileges as the Visual Studio Code application.\u003c/li\u003e\n\u003cli\u003eSuccessful exploitation grants the attacker remote code execution capabilities, potentially leading to complete control over the victim's system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eA successful exploitation of CVE-2026-44190 allows a remote attacker to execute arbitrary commands on the victim's system with the privileges of the Visual Studio Code application. This could lead to a full system compromise, enabling the attacker to install malware, exfiltrate sensitive data, or establish persistent access. All users of the Ansible Lightspeed Visual Studio Code extension are at risk, regardless of their underlying operating system (Windows, Linux, or macOS). The high CVSS score of 7.8 indicates a significant threat severity, implying that exploitation could have a critical impact on the confidentiality, integrity, and availability of the affected system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-44190 by updating the Ansible Lightspeed Visual Studio Code extension to a patched version immediately.\u003c/li\u003e\n\u003cli\u003eEnsure that Visual Studio Code and all its extensions are regularly updated to mitigate known vulnerabilities.\u003c/li\u003e\n\u003cli\u003eEducate users about the risks of opening or executing untrusted projects from unknown sources to prevent initial access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T12:21:11Z","date_published":"2026-07-22T12:21:11Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ansible-lightspeed-vscode-rce/","summary":"A command injection vulnerability (CVE-2026-44190, CWE-78) in the Ansible Lightspeed Visual Studio Code extension allows remote attackers to execute arbitrary commands on a user's system due to improper validation of the `ansible.python.activationScript` setting, leading to complete system control when a malicious project is opened.","title":"Ansible Lightspeed VS Code Extension Command Injection Vulnerability (CVE-2026-44190)","url":"https://feed.craftedsignal.io/briefs/2026-07-ansible-lightspeed-vscode-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Vscode-Extension","version":"https://jsonfeed.org/version/1.1"}