CVE-2026-44191

Description

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when executing a playbook. Successful exploitation leads to remote code execution (RCE) on the victim's machine with the privileges of the Visual Studio Code user, potentially resulting in a complete system compromise.

Statement

This is an Important command injection vulnerability in the Visual Studio Code Ansible Lightspeed extension. It allows an attacker to achieve Remote Code Execution (RCE) on the victim's machine with the privileges of the Visual Studio Code user. This can occur when opening a malicious workspace or manually executing a playbook, leading to a complete compromise of the user's system.

Note the VS Code extension is distributed via VS Code Marketplace, not shipped in AAP RPMs or containers. The vulnerable code does not exist in any AAP-shipped artifact.

Mitigation

To mitigate this issue, users of the Visual Studio Code Ansible Lightspeed extension should exercise caution and avoid opening untrusted workspaces or executing playbooks from unverified sources. Carefully review the contents of `ansible.executionEnvironment.containerOptions` and `ansible.executionEnvironment.volumeMounts` settings within the extension's configuration, especially when dealing with new or external projects, to prevent the injection of malicious commands.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.8N/A7.8
Attack VectorLocalN/ALocal
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionRequiredN/ARequired
ScopeUnchangedN/AUnchanged
ConfidentialityHighN/AHigh
Integrity ImpactHighN/AHigh
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

cve.org: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Confidentiality,Integrity,Availability,Non-Repudiation

Technical Impact: Execute Unauthorized Code or Commands; DoS: Crash, Exit, or Restart; Read Files or Directories; Modify Files or Directories; Read Application Data; Modify Application Data; Hide Activities

Attackers could execute unauthorized operating system commands, which could then be used to disable the product, or read and modify data for which the attacker does not have permissions to access directly. Since the targeted application is directly executing the commands instead of the attacker, any malicious activities may appear to come from the application or the application's owner.

Acknowledgements

This issue was discovered by Laura Pardo (Red Hat Inc.).

Frequently Asked Questions

Want to get errata notifications? Sign up here.