Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
7.0
CVE-2026-19515PATCHED
wso2 · wso2 integrator: mi for visual studio code

OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution

Description

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary operating system commands through the unit test execution flow. Successful exploitation of this vulnerability could lead to the execution of arbitrary OS commands on the system where the VS Code extension is running. The extent of the impact is dependent on the privileges of the user account under which VS Code is operating. Exploitation requires the user to grant workspace trust to the malicious project and subsequently trigger the unit test execution.

Affected Products

VendorProductVersions
wso2wso2 integrator: mi for visual studio code0

References

  • https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5854/(vendor-advisory)

Related News (1 articles)

Tier C
VulDB12d ago
CVE-2026-19515 | WSO2 Integrator up to 4.1.3 MI for Visual Studio Code os command injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.0 HIGH
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5854/
CWECWE-78
PublishedSep 15, 2026
Last enriched12d ago
Trending Score7
Source articles1
Independent1
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-5430
Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover
Trending: 55
MEDIUMCVE-2025-5802
Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery
Trending: 7
LOWCVE-2025-13166
Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery
Trending: 4
MEDIUMCVE-2026-4103
Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution
Trending: 4
MEDIUMCVE-2026-3096
Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft
Trending: 3

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 15, 2026
Discovered by ZDM
Sep 15, 2026
Patch Available
Sep 15, 2026