PT-2026-2793 · Vmware · Spring Cli Vscode Extension

Yue Liu

·

Published

2026-01-14

·

Updated

2026-01-14

·

CVE-2026-22718

CVSS v3.1

6.8

Medium

AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Spring CLI VSCode extension versions through 0.9.0
Description The VSCode extension for Spring CLI is susceptible to a command injection flaw. This allows an attacker to execute arbitrary commands locally if a user is tricked into triggering a vulnerable workflow. The extension is end-of-life and there is no patch available. The issue can lead to command execution on the user's machine.
Recommendations Remove the Spring CLI VSCode extension and migrate to supported Spring tooling.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-22718

Affected Products

Spring Cli Vscode Extension