High severity7.8NVD Advisory· Published Jul 22, 2026· Updated Jul 23, 2026
CVE-2026-44190
CVE-2026-44190
Description
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the ansible.python.activationScript setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or executes a specially crafted project, an attacker could exploit this to gain complete control over the user's system with the privileges of the Visual Studio Code application.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
1- Ansible: Five Vulnerabilities Disclosed Together Affecting VS Code Extension, AWX, and Community ContentVypr Intelligence · Jul 22, 2026