CVE-2026-22718: EOL Spring CLI Tool for VS Code Found Vulnerable to Command Injection
ID: 50778287-303e-59ec-88c2-89ad78011d90
STIX ID: report--50778287-303e-59ec-88c2-89ad78011d90
Feed Name: securityonline.info
A command-injection vulnerability (CVE-2026-22718, CVSS 6.6) has been discovered in the now-retired Spring CLI VS Code extension (version 0.9.0 and older) that can allow attackers to execute arbitrary commands on a developer's machine; because the extension reached end-of-life with no patch planned, the advisory urges users to remove the extension immediately. The flaw was responsibly reported by researcher Yue Liu and highlights the need to audit and remove unsupported extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
