---
id: CVE-2026-19515
title: >-
  The WSO2 Integrator MI VS Code extension fails to properly sanitize or
  validate user-supplied input when processing Micro Integrator projects opened
  from untrusted sources
summary: >-
  The WSO2 Integrator MI VS Code extension fails to properly sanitize or
  validate user-supplied input when processing Micro Integrator projects opened
  from untrusted sources. This allows a crafted project to inject and execute
  arbitrary op…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: WSO2
product: 'WSO2 Integrator: MI for Visual Studio Code'
affected:
  - integrator_mi_for_visual_studio_code <= 4.1.3
published: '2026-09-15'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:13:15.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19515'
references:
  - url: >-
      https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5854/
    label: ed10eef1-636d-4fbe-9993-6890dfa878f8
tags:
  - nvd
  - cve.org
epss: 0.00138
epssPercentile: 0.02633
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T12:50:00.699078Z'
ingestedAt: '2026-09-15T10:35:28.512Z'
---

## Overview

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary operating system commands through the unit test execution flow.

Successful exploitation of this vulnerability could lead to the execution of arbitrary OS commands on the system where the VS Code extension is running. The extent of the impact is dependent on the privileges of the user account under which VS Code is operating. Exploitation requires the user to grant workspace trust to the malicious project and subsequently trigger the unit test execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
