Impact
OS Command Injection occurs when the WSO2 Integrator MI VS Code extension does not sanitize user-supplied input while processing Micro Integrator projects opened from untrusted arbitrary operating system commands during the unit test execution flow, leading to code execution on the host running the extension. The extent of the impact depends on the privileges of the user account under which VS Code operates, and the vulnerability requires the attacker to first grant workspace trust and then trigger a unit test.
Affected Systems
The vulnerability affects the WSO2 Integrator MI for VisualSO2. No specific version information was listed, implying that all currently supported releases are potentially impacted until the vendor releases a patched version.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation within the short term, and the vulnerability is not yet in the CISA KEV catalog. Successful exploitation requires a local user who trusts a malicious project, which limits the attack surface. Nevertheless, the ability to execute arbitrary OS commands is a critical risk that can lead to full system compromise if the user runs VS Code with elevated privileges.
OpenCVE Enrichment