Spring CLI Vulnerability Allows Attackers to Execute Commands on User Systems
ID: 301d7e59-4b2f-5934-a841-777880a3a8d0
STIX ID: report--301d7e59-4b2f-5934-a841-777880a3a8d0
Feed Name: GBHackers
Threat Score
**Command-injection vulnerability in Spring CLI VSCode extension (CVE-2026-22718)** — A command-injection flaw in the deprecated Spring CLI VSCode extension (versions ≤ 0.9.0) allows attackers with local access and user interaction to execute arbitrary commands; it is rated MEDIUM (CVSS 6.8) and, because the extension is end-of-life, removal is the recommended mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
