CVE Explorer
CVE-2026-12856
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user clicks a specially crafted link within a JavaDoc hover popup, an attacker can execute arbitrary VS Code commands, which can lead to full system compromise in trusted workspaces.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
2 source assertions{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:openshift_devspaces:3.29::el9"],"defaultStatus":"affected","packageName":"devspaces/pluginregistry-rhel9","product":"Red Hat OpenShift Dev Spaces 3.29","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1782989367","versionType":"rpm"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/adp/1/affected/0
{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:openshift_devspaces:3.29::el9"],"defaultStatus":"affected","packageName":"devspaces/pluginregistry-rhel9","product":"Red Hat OpenShift Dev Spaces 3.29","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"1782989367","versionType":"rpm"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/cna/affected/0
Provider-owned CVSS observations
2 source assertions{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/adp/1/metrics/1/cvssV3_1
{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/cna/metrics/1/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-88","description":"Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/adp/1/problemTypes/0/descriptions/0
{"cweId":"CWE-88","description":"Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/cna/problemTypes/0/descriptions/0
Source references
8 source assertions{"name":"RHSA-2026:36820","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:36820"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/cna/references/0
{"tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:36820"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/adp/1/references/3
{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-12856"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/adp/1/references/0
{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-12856"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/cna/references/1
{"name":"RHBZ#2491278","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491278"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/cna/references/2
{"name":"RHBZ#2491278","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491278"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/adp/1/references/1
{"url":"https://github.com/redhat-developer/vscode-java/security/advisories/GHSA-7qv8-6qrw-3crv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/cna/references/3
{"tags":["x_sadp-csaf-vex"],"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12856.json"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:64ca07b5dc84fcdee40312604197de982f24c8df864fc49cdeed137dffd25302 · sha256:6be94987546e3439… · /containers/adp/1/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.