Junglewise Threat Intelligence

CVE-2026-44187: Red Hat Ansible Lightspeed plaintext API key storage in VS Code extension

CVE-2026-44187 · Severity: low · CVSS 3.3 · Published 2026-07-22

Technologies: Red Hat Ansible Automation Platform 2, Red Hat Ansible Lightspeed extension for Visual Studio Code. Vendors: Red Hat.

Executive brief

A security flaw in the Ansible Lightspeed extension for Visual Studio Code allows sensitive Google Gemini API keys to be stored in plain text. An attacker with physical access to a developer's computer, or malicious software running on that computer, could steal these keys. This could lead to unauthorized use of the victim's AI service quota and potential exposure of associated account data.

Technical details

An information disclosure vulnerability exists in the Ansible Lightspeed extension for Visual Studio Code due to the insecure storage of credentials (CWE-256). The extension writes the Google Gemini API key in plain text to the user's configuration file and output log files. A local attacker with low privileges or malware executing in the user's context can read these files to obtain the API key. This allows for the unauthorized consumption of the user's API quota. The issue was identified in Red Hat Ansible Automation Platform versions 2.5 and 2.6.

Affected products

  • Red Hat Ansible Lightspeed extension for Visual Studio Code unspecified
  • Red Hat Ansible Automation Platform 2 2.5, 2.6

Timeline

  • 2026-05-05: other: Initial report in Red Hat Bugzilla
  • 2026-07-22: disclosed: NVD publication date

References

Related threats