CVE-2026-44187 Details
Description
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's configuration file and writes it to output log files. This information disclosure can lead to the attacker obtaining the API credential and potentially consuming the user's API quota.
A vulnerability exists in the Ansible Lightspeed extension for Visual Studio Code, allowing local attackers or malware with user privileges to access the Google Gemini API key. The extension stores the API key in plain text in the user's configuration file and logs it in output files. This exposure could lead to unauthorized use of the API key and consumption of the user's API quota.
Users should rotate and delete any exposed Google Gemini API keys. The API key must be manually removed from the user's Visual Studio Code settings file. Additionally, log files that may contain the API key should be securely handled or deleted.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-44187 | [email protected] | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2466765 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-256 | Plaintext Storage of a Password | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |