Security Advisory WSO2-2026-5854/CVE-2026-19515¶
Published: September 15, 2026
Version: 1.0.0
Severity: High
CVSS Score: 7.0 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
CVE IDs: CVE-2026-19515
AFFECTED PRODUCTS¶
- WSO2 Integrator: MI for Visual Studio Code 4.1.3 and below
OVERVIEW¶
OS command injection vulnerability in the WSO2 Integrator: MI VS Code extension via unit test run.
DESCRIPTION¶
A user who accesses an untrusted Micro Integrator project via the extension may trigger the execution of arbitrary operating system commands. Exploitation requires the user to grant workspace trust to the project and then run unit tests.
IMPACT¶
This vulnerability could lead to arbitrary OS command execution on the system where the VS Code extension is running. The extent of the impact depends on the privileges of the user account under which VS Code is operating.
SOLUTION¶
Users of affected versions should upgrade to WSO2 Integrator: MI for Visual Studio Code v4.1.4 or above.
CREDITS¶
WSO2 thanks, Mykhailo Kholiev for responsibly reporting the identified issue and working with us as we addressed it.