HomeSecuritySpring vulnerability allows commands to be executed on the user's PC

Spring vulnerability allows execution of commands on user's PC

A command injection vulnerability in the Spring CLI for VS Code poses a security risk to developers who still use the outdated tool.

See also: New VVS Stealer targets Discord accounts via Python

Spring vulnerability

The vulnerability, codenamed CVE-2026-22718, allows attackers to execute arbitrary commands on affected systems, resulting in a medium severity impact.

The vulnerability affects versions 0.9.0 and earlier of the Spring CLI extension for VS Code. Although the tool reached end of life on May 14, 2025, the Spring team has published the CVE to ensure timely and accurate notification to users who may still have the extension installed.

The command injection flaw is exploited locally and requires user interaction to trigger. An attacker with local access could alter the way the extension handles inputs, injecting malicious commands, and ultimately gain the ability to execute code on the developer's system.

See also: New wave of GlassWorm malware targets Mac computers

Spring vulnerability allows execution of commands on user's PC

The vulnerability received a CVSS score of 6.3 (Medium), reflecting the local attack vector and the requirement for user interaction. However, the potential impact remains significant, as successful exploitation could allow sensitive files to be read, system settings to be modified, and development environments containing source code and credentials to be compromised.

All versions of the Spring CLI extension for VS Code up to 0.9.0 remain vulnerable. Since the extension officially reached its end of life (EOL) in May 2025, no security fixes have been released or will be released. Organizations and individual developers who have the Spring CLI extension for VS Code installed should prioritize its removal as a matter of urgency. The disclosure of the vulnerability highlights the importance of retiring outdated development tools.

See also: OAuth device code phishing: New technique for compromising Microsoft 365 accounts

Spring vulnerability allows execution of commands on user's PC

The Spring team recommends removing the extension from development environments immediately. Users can uninstall it via the VS Code extension marketplace or manually delete the extension folder.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS