Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44190

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 7.8

Описание

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the ansible.python.activationScript setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or executes a specially crafted project, an attacker could exploit this to gain complete control over the user's system with the privileges of the Visual Studio Code application.

Отчет

This is an Important command injection flaw in the Ansible Lightspeed Visual Studio Code extension. It enables arbitrary code execution on a user's system with VS Code process privileges if a malicious project's .vscode/settings.json is opened or a playbook executed without prior validation. This could lead to a complete system compromise. Note the VS Code extension is distributed via VS Code Marketplace, not shipped in AAP RPMs or containers.

Меры по смягчению последствий

To mitigate this issue, configure the ansible.python.activationScript setting to "User" scope only within Visual Studio Code settings. This prevents untrusted project configurations from defining this setting in .vscode/settings.json. Users should always review the contents of .vscode/settings.json before opening or executing playbooks from untrusted sources. This action does not require a service restart or reload.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-dev-tools-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/ansible-dev-tools-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-dev-toolsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2466762ansible-lightspeed: Ansible Lightspeed Visual Studio Code extension: Arbitrary code execution via command injection in activation script setting

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
18 дней назад

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or executes a specially crafted project, an attacker could exploit this to gain complete control over the user's system with the privileges of the Visual Studio Code application.

CVSS3: 7.8
github
18 дней назад

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or executes a specially crafted project, an attacker could exploit this to gain complete control over the user's system with the privileges of the Visual Studio Code application.

7.8 High

CVSS3