What is CVE-2026-44190?
A Command Injection vulnerability (CWE-78) has been discovered in the Ansible Lightspeed Visual Studio Code extension. A remote attacker can exploit the `ansible.python.activationScript` setting to execute unauthorized commands on the user's system. Users are advised to update the extension as soon as possible.
Azərbaycanca: Ansible Lightspeed Visual Studio Code genişlənməsində Command Injection (CWE-78) zəifliyi aşkarlanıb. Uzaqdan hücumçu `ansible.python.activationScript` parametrindən sui-istifadə edərək istifadəçi sistemində icazəsiz əmrlər icra edə bilər. İstifadəçilərə genişlənməni mümkün qədər tez yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What vulnerability has been discovered in the Ansible Lightspeed extension?
A Command Injection vulnerability (CWE-78) that exploits the `ansible.python.activationScript` setting has been discovered.
What can a remote attacker do by exploiting this vulnerability?
A remote attacker can execute unauthorized commands on the user's system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.