Bug 2466763 (CVE-2026-44189) - CVE-2026-44189 ansible-lightspeed: Visual Studio Code Ansible Lightspeed Extension: Arbitrary Code Execution via Malicious Playbook Filename
Summary: CVE-2026-44189 ansible-lightspeed: Visual Studio Code Ansible Lightspeed Exte...
Keywords:
Status: NEW
Alias: CVE-2026-44189
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-05 15:13 UTC by OSIDB Bzimport
Modified: 2026-07-22 12:02 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-05 15:13:18 UTC
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. This could result in a full system compromise, including the exfiltration of sensitive data, modification of project files, and permanent data loss.


Note You need to log in before you can comment on or make changes to this bug.