Skip to content
Spring CLI Tool Vulnerability Enables Command Execution

Spring CLI Tool Vulnerability Enables Command Execution

First seen 14 Jan 2026, 17:51 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A command injection vulnerability in the Spring CLI VSCode extension allows attackers to execute arbitrary commands on affected machines. This flaw, tracked as CVE-2026-22718, impacts developers using version 0.9.0 and earlier of the tool, which has reached its end-of-life. The vulnerability is categorized with a medium severity level.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track CVE-2026-22718 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed