Vulnerability record · CVE-2026-12856 · published 29 June 2026
CVE-2026-12856: Redhat openshift dev spaces argument injection vulnerability
Redhat · Openshift Dev Spaces
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces.
Description
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:36820 | |
| https://access.redhat.com/security/cve/CVE-2026-12856 | MitigationVendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2491278 | Issue TrackingVendor Advisory |
| https://github.com/redhat-developer/vscode-java/security/advisories/GHSA-7qv8-6qrw-3crv | Broken Link |
| https://access.redhat.com/errata/RHSA-2026:36820 | |
| https://access.redhat.com/security/cve/CVE-2026-12856 | MitigationVendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2491278 | Issue TrackingVendor Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12856.json | Vendor Advisory |
Track CVE-2026-12856 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-12856), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.