Impact
A flaw in the Ansible Lightspeed extension for Visual Studio Code allows an attacker with local access or malware running as the user to read the Google Gemini API key. The extension stores the key in plain text in the user’s configuration file and writes it to output logs, resulting in a data‑at‑rest disclosure (CWE‑256) that could enable the attacker to consume the user’s API quota.
Affected Systems
The vulnerability affects Red Hat Ansible Automation Platform 2 through its Ansible Lightspeed extension for Visual Studio Code. No specific patch or version details beyond that platform version are listed.
Risk and Exploitability
The CVSS score is 3.3, indicating a low‑moderate risk level, while the EPSS score is < 1 %, meaning the probability of active exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. Attackers need local or user‑level access, limiting the threat scope, but once the key is disclosed they could exhaust the user’s API quota and cause service interruptions.
OpenCVE Enrichment