Impact
A command injection flaw in the Ansible Lightspeed Visual Studio Code extension allows a remote attacker to execute arbitrary commands with the privileges of the Visual Studio Code process. The vulnerability stems from the extension's handling of the ansible.python.activationScript setting, which accepts an untrusted file path without proper validation. When a user opens or runs a playbook that contains a maliciously crafted project configuration, an attacker can gain full control over the user's system.
Affected Systems
The flaw affects the Red Hat Ansible Platform 2, specifically the Ansible Lightspeed Visual Studio Code extension. No specific patch versions are listed; the issue applies to the extension as distributed with the platform.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation in the near term. The vulnerability is not listed in CISA KEV. Likely exploitation requires a user to open or execute a specially crafted project, making social engineering or trusted-file manipulation a probable attack vector. Consequently, the risk is moderate, but the potential impact is complete system compromise under the VS Code user context.
OpenCVE Enrichment