A vulnerability was found in Shopify ruby-lsp up to 0.10.3 and classified as critical. This impacts an unknown function of the file .vscode/settings.json of the component VS Code Extension. The manipulation results in os command injection.

This vulnerability is reported as CVE-2026-48122. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.