Executive brief
A security vulnerability exists in the Ansible Lightspeed extension for Visual Studio Code, a tool used by developers to automate IT tasks. If a developer opens a malicious project file, an attacker can execute unauthorized commands on their computer. This could lead to a total system takeover, allowing the attacker to steal data or disrupt operations using the same permissions as the developer's code editor.
Technical details
A command injection vulnerability (CWE-78) exists in the Ansible Lightspeed Visual Studio Code extension due to improper validation of the `ansible.python.activationScript` setting. This setting, which is intended to point to a virtual environment activation script, fails to sanitize input as a strict file path. An attacker can exploit this by providing a specially crafted project that includes malicious commands within this configuration. When a victim opens or executes the project, the extension executes the injected commands with the privileges of the VS Code application. The vulnerability is tracked as CVE-2026-44190 and requires user interaction (opening a project) to trigger.
Affected products
- Red Hat Ansible Lightspeed Visual Studio Code extension unspecified
- Red Hat Red Hat Ansible Automation Platform 2 2.0
Timeline
- 2026-05-05: other: Vulnerability reported to Red Hat Bugzilla
- 2026-07-22: disclosed: CVE published to NVD