CVE-2026-12856

A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:openshift_dev_spaces:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-29 14:16

Updated : 2026-07-15 02:18


NVD link : CVE-2026-12856

Mitre link : CVE-2026-12856

CVE.ORG link : CVE-2026-12856


JSON object : View

Products Affected

redhat

  • openshift_dev_spaces
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')