PT-2026-2793 · Vmware · Spring Cli Vscode Extension

Yue Liu

·

Publicado

2026-01-14

·

Atualizado

2026-01-14

·

CVE-2026-22718

CVSS v3.1

6.8

Média

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Spring CLI VSCode extension versions through 0.9.0
Description The VSCode extension for Spring CLI is susceptible to a command injection flaw. This allows an attacker to execute arbitrary commands locally if a user is tricked into triggering a vulnerable workflow. The extension is end-of-life and there is no patch available. The issue can lead to command execution on the user's machine.
Recommendations Remove the Spring CLI VSCode extension and migrate to supported Spring tooling.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22718

Produtos afetados

Spring Cli Vscode Extension