๐Ÿ” CVE Alert

CVE-2026-12856

HIGH 8.8

Vscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extension

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces.

CWE CWE-88
Vendor red hat
Product red hat openshift dev spaces
Published Jun 29, 2026
Last Updated Jun 29, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat openshift dev spaces

Be the first to know when new high vulnerabilities affecting red hat red hat openshift dev spaces are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Red Hat / Red Hat OpenShift Dev Spaces
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-12856 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2491278 github.com: https://github.com/redhat-developer/vscode-java/security/advisories/GHSA-7qv8-6qrw-3crv

Credits

Red Hat would like to thank byte256 for reporting this issue.