No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, users of the Visual Studio Code Ansible Lightspeed extension should exercise caution and avoid opening untrusted workspaces or executing playbooks from unverified sources. Carefully review the contents of `ansible.executionEnvironment.containerOptions` and `ansible.executionEnvironment.volumeMounts` settings within the extension's configuration, especially when dealing with new or external projects, to prevent the injection of malicious commands.
Wed, 22 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Jul 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing a playbook. Successful exploitation leads to remote code execution (RCE) on the victim's machine with the privileges of the Visual Studio Code user, potentially resulting in a complete system compromise. | |
| Title | Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settings | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 | |
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-22T18:48:19.980Z
Reserved: 2026-05-05T15:02:54.444Z
Link: CVE-2026-44191
Updated: 2026-07-22T18:30:56.713Z
No data.
No data.
OpenCVE Enrichment
No data.