A command injection vulnerability in the end-of-life Spring CLI VS Code extension allows arbitrary command execution on a developer’s machine, tracked as CVE-2026-22718. The issue affects Spring CLI VSCode Extension v0.9.0 and earlier and is described as a local attack scenario requiring user interaction (e.g., interacting with crafted content/projects) to trigger execution in the context of the logged-in user, potentially enabling access to sensitive files, credentials, source code, and system configuration changes.
The extension reached EOL on May 14, 2025, and the Spring team issued the CVE despite the retirement to improve security communication for users who may still have it installed. Both reports state there is no patch due to unsupported status; the primary mitigation is to uninstall/remove the extension and transition to supported Spring development tooling. Reported severity is medium (one source cites CVSS 6.3, another CVSS 6.6), and the vulnerability was responsibly reported by researcher Yue Liu.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
Spring publicly disclosed CVE-2026-22718, warning that the end-of-life Spring CLI VS Code extension contains a command injection issue and that no fix will be released because the product is unsupported. Users were advised to uninstall the extension and move to supported alternatives.
Security researcher Yue Liu responsibly disclosed a command injection vulnerability affecting the Spring CLI VS Code extension, version 0.9.0 and earlier. The flaw could allow arbitrary command execution on a developer's machine through crafted project content or files.
The Spring CLI extension for Visual Studio Code reached end-of-life and became unsupported. Later advisories noted that communication around the EOL status could have been better.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.