Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44189

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 7.8

Описание

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. This could result in a full system compromise, including the exfiltration of sensitive data, modification of project files, and permanent data loss.

Отчет

This Important vulnerability in the Visual Studio Code Ansible Lightspeed extension allows for command injection via malicious playbook filenames. Exploitation requires user interaction to run a specially crafted playbook, leading to arbitrary code execution with the privileges of the user running VS Code. This could result in significant impact to confidentiality, integrity, and availability of user data and the system. Note the VS Code extension is distributed via VS Code Marketplace, not shipped in AAP RPMs or containers. The vulnerable code does not exist in any AAP-shipped artifact.

Меры по смягчению последствий

To mitigate this issue, users of the Visual Studio Code Ansible Lightspeed extension should avoid running Ansible playbooks from untrusted sources or those with suspicious filenames. Always verify the origin and integrity of playbook files before execution to prevent command injection. This operational control limits exposure by preventing the processing of maliciously crafted filenames.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-dev-tools-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/ansible-dev-tools-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-dev-toolsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2466763ansible-lightspeed: Visual Studio Code Ansible Lightspeed Extension: Arbitrary Code Execution via Malicious Playbook Filename

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
18 дней назад

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. This could result in a full system compromise, including the exfiltration of sensitive data, modification of project files, and permanent data loss.

CVSS3: 7.8
github
18 дней назад

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. This could result in a full system compromise, including the exfiltration of sensitive data, modification of project files, and permanent data loss.

7.8 High

CVSS3