#VU121272 Command Injection in Spring CLI VSCode Extension - CVE-2026-22718
Published: January 13, 2026
Spring CLI VSCode Extension
Spring
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the system.
The vulnerability exists due to insufficient input validation. A remote attacker can trick the victim into opening a specially crafted file and execute arbitrary commands.
Remediation
Software is no longer supported by the vendor and there will be no security patch. It is recommended to no longer use this extension.