What is CVE-2026-44191?
A command injection vulnerability (CWE-78) has been found in Microsoft's Visual Studio Code Ansible Lightspeed extension. Improper handling of the `ansible.executionEnvironment.containerOptions` and `ansible.executionEnvironment.volumeMounts` settings allows an attacker to inject shell separators and execute arbitrary commands. Users of this extension should apply updates immediately.
Azərbaycanca: Microsoft Visual Studio Code-un Ansible Lightspeed genişlənməsində əmr yeridilməsi boşluğu (CWE-78) aşkar edilib. `ansible.executionEnvironment.containerOptions` və `ansible.executionEnvironment.volumeMounts` parametrlərinin düzgün idarə olunmaması nəticəsində hücumçu shell separatorları yeridərək ixtiyari əmrlər icra edə bilər. Bu genişlənmədən istifadə edən istifadəçilər təcili yeniləmə tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which extension is affected by CVE-2026-44191?
Microsoft Visual Studio Code's Ansible Lightspeed extension is affected.
Through which settings can an attacker execute arbitrary commands?
By injecting shell separators into the `ansible.executionEnvironment.containerOptions` and `ansible.executionEnvironment.volumeMounts` settings.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.