Spring CLI Tool Vulnerability Enables Command Execution

Spring CLI Tool Vulnerability Enables Command Execution

First seen 14 Jan 2026, 17:51 UTC GbhackersCybersecuritynewsCyberpress 92% similarity 25.9

Article Content

Browse articles
ThreatCluster

A command injection vulnerability in the Spring CLI VSCode extension allows attackers to execute arbitrary commands on affected machines. This flaw, tracked as CVE-2026-22718, impacts developers using version 0.9.0 and earlier of the tool, which has reached its end-of-life. The vulnerability is categorized with a medium severity level.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story