What is CVE-2026-44189?
A command injection vulnerability exists in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. An attacker can exploit this by crafting a playbook filename with special characters that execute malicious commands when run. Users should update the extension to the patched version immediately.
Azərbaycanca: Visual Studio Code-un Ansible Lightspeed genişlənməsində komanda injection zəifliyi aşkarlanıb. Təcavüzkar xüsusi simvollar olan fayl adı ilə zərərli playbook hazırlayaraq istifadəçi işə saldıqda kod icrasına səbəb ola bilər. Dərhal genişlənməni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which Visual Studio Code extension is affected by CVE-2026-44189?
This vulnerability affects the Visual Studio Code Ansible Lightspeed extension.
What should users do to protect against CVE-2026-44189?
Users should immediately update the Ansible Lightspeed extension to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.