CVE-2026-44190

HIGH

Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script setting

Title source: cna
STIX 2.1

Description

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or executes a specially crafted project, an attacker could exploit this to gain complete control over the user's system with the privileges of the Visual Studio Code application.

References (2)

Core 2
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-44190
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2466762
https://bugzilla.redhat.com/show_bug.cgi?id=2466762

Scores

CVSS v3 7.8
EPSS 0.0043
EPSS Percentile 35.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
Red Hat/Red Hat Ansible Automation Platform 2
Published Jul 22, 2026
Tracked Since Jul 22, 2026