Command Injection in Spring CLI VSCode Extension - CVE-2026-22718
Published: January 13, 2026
Spring CLI VSCode Extension
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands on the system.
The vulnerability exists due to insufficient input validation. A remote attacker can trick the victim into opening a specially crafted file and execute arbitrary commands.
How to mitigate CVE-2026-22718
Software is no longer supported by the vendor and there will be no security patch. It is recommended to no longer use this extension.