What is CVE-2026-44187?
CVE-2026-44187 is a vulnerability in the Ansible Lightspeed extension for Visual Studio Code. A local attacker or malware with user privileges can read the Google Gemini API key due to insecure plain text storage. Users should temporarily disable the extension and await an official patch.
Azərbaycanca: CVE-2026-44187, Ansible Lightspeed VS Code extension-da aşkar edilmiş zəiflikdir. Yerli təcavüzkar və ya istifadəçi səviyyəsində işləyən malware, Google Gemini API açarını plain text formatında oxuya bilər. İstifadəçilər extension-u müvəqqəti deaktiv etməli və rəsmi yamağı gözləməlidir.
Related CVEs
link basis: shared vendor: Google
FAQ1
What product is affected by CVE-2026-44187?
This vulnerability affects the Ansible Lightspeed VS Code extension.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.