logo

CVE-2026-22718: EOL Spring CLI Tool for VS Code Found Vulnerable to Command Injection

ID: 50778287-303e-59ec-88c2-89ad78011d90

STIX ID: report--50778287-303e-59ec-88c2-89ad78011d90

Feed Name: securityonline.info

Threat Score
50/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Ddos

...
...

A command-injection vulnerability (CVE-2026-22718, CVSS 6.6) has been discovered in the now-retired Spring CLI VS Code extension (version 0.9.0 and older) that can allow attackers to execute arbitrary commands on a developer's machine; because the extension reached end-of-life with no patch planned, the advisory urges users to remove the extension immediately. The flaw was responsibly reported by researcher Yue Liu and highlights the need to audit and remove unsupported extensions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.