Home
MEDIUM: 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:LDefault status
unaffected
0.9.0 and older
affected
Description
The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
0.9.0 and older
References
spring.io/security/cve-2026-22718