A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces.
History

Mon, 29 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces.
Title Vscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extension
First Time appeared Redhat
Redhat openshift Devspaces
Weaknesses CWE-88
CPEs cpe:/a:redhat:openshift_devspaces:3
Vendors & Products Redhat
Redhat openshift Devspaces
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-06-29T12:38:26.696Z

Reserved: 2026-06-22T06:09:52.759Z

Link: CVE-2026-12856

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T14:30:18Z