CVE-2026-22718: Spring CLI Vscode Extension

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.

Affected products

  • Spring CLI Vscode Extension: up to and including 0.9.0

Published 2026-01-14. Last modified 2026-06-17.