Cybersecuritynews
Spring CLI Tool Vulnerability Enables Command Execution
First seen 14 Jan 2026, 17:51 UTC
•

•92% similarity
•25.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
Browse articles
A command injection vulnerability in the Spring CLI VSCode extension allows attackers to execute arbitrary commands on affected machines. This flaw, tracked as CVE-2026-22718, impacts developers using version 0.9.0 and earlier of the tool, which has reached its end-of-life. The vulnerability is categorized with a medium severity level.
ThreatCluster AI
How this analysis works