{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-44190","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2026-05-05T15:02:54.443Z","datePublished":"2026-07-22T12:06:42.591Z","dateUpdated":"2026-07-23T13:50:44.922Z"},"containers":{"cna":{"title":"Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script setting","metrics":[{"other":{"content":{"value":"Important","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or executes a specially crafted project, an attacker could exploit this to gain complete control over the user's system with the privileges of the Visual Studio Code application."}],"affected":[{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-25/ansible-dev-tools-rhel8","defaultStatus":"affected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-automation-platform-26/ansible-dev-tools-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]},{"vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"ansible-dev-tools","defaultStatus":"affected","cpes":["cpe:/a:redhat:ansible_automation_platform:2"]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-44190","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466762","name":"RHBZ#2466762","tags":["issue-tracking","x_refsource_REDHAT"]}],"datePublic":"2026-07-22T11:59:27.358Z","problemTypes":[{"descriptions":[{"cweId":"CWE-78","description":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","workarounds":[{"lang":"en","value":"To mitigate this issue, configure the `ansible.python.activationScript` setting to \"User\" scope only within Visual Studio Code settings. This prevents untrusted project configurations from defining this setting in `.vscode/settings.json`. Users should always review the contents of `.vscode/settings.json` before opening or executing playbooks from untrusted sources. This action does not require a service restart or reload."}],"timeline":[{"lang":"en","time":"2026-05-05T15:02:26.073Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-07-22T11:59:27.358Z","value":"Made public."}],"credits":[{"lang":"en","value":"This issue was discovered by Laura Pardo (Red Hat Inc.)."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-07-22T12:06:42.591Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-23T13:50:37.312218Z","id":"CVE-2026-44190","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-23T13:50:44.922Z"}}]}}