Junglewise Threat Intelligence

CVE-2026-44190: Red Hat Ansible Lightspeed command injection in VS Code extension

CVE-2026-44190 · Severity: high · CVSS 7.8 · Published 2026-07-22

Vendors: Red Hat.

Executive brief

A security vulnerability exists in the Ansible Lightspeed extension for Visual Studio Code, a tool used by developers to automate IT tasks. If a developer opens a malicious project file, an attacker can execute unauthorized commands on their computer. This could lead to a total system takeover, allowing the attacker to steal data or disrupt operations using the same permissions as the developer's code editor.

Technical details

A command injection vulnerability (CWE-78) exists in the Ansible Lightspeed Visual Studio Code extension due to improper validation of the `ansible.python.activationScript` setting. This setting, which is intended to point to a virtual environment activation script, fails to sanitize input as a strict file path. An attacker can exploit this by providing a specially crafted project that includes malicious commands within this configuration. When a victim opens or executes the project, the extension executes the injected commands with the privileges of the VS Code application. The vulnerability is tracked as CVE-2026-44190 and requires user interaction (opening a project) to trigger.

Affected products

  • Red Hat Ansible Lightspeed Visual Studio Code extension unspecified
  • Red Hat Red Hat Ansible Automation Platform 2 2.0

Timeline

  • 2026-05-05: other: Vulnerability reported to Red Hat Bugzilla
  • 2026-07-22: disclosed: CVE published to NVD

References