Eclipse Open Vsx
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Eclipse Open Vsx.
By the Year
In 2026 there have been 2 vulnerabilities in Eclipse Open Vsx with an average score of 4.1 out of ten. Last year, in 2025 Open Vsx had 2 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Open Vsx in 2026 could surpass last years number. Last year, the average CVE base score was greater by 1.20
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 4.10 |
| 2025 | 2 | 5.30 |
It may take a day or so for new Open Vsx vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Eclipse Open Vsx Security Vulnerabilities
Open VSX Registry <1.0.2 XSS/CSRF via /vscode/unpkg/ no CSP
CVE-2026-13323
4.1 - Medium
- July 01, 2026
In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An unauthenticated attacker can register a publisher account, upload a VSIX containing a crafted HTML payload, and induce an authenticated user to visit the resulting URL. The browser renders the file inline in the open-vsx.org origin context, enabling session token exfiltration, persistent Personal Access Token (PAT) generation, and unauthorized publication of malicious extension versions. Because Open VSX extensions are distributed to VS Code, VSCodium, Cursor, Windsurf, and compatible editors, a compromised extension update constitutes a supply chain attack against all downstream users.
XSS
Open VSX Registry SVG XSS via Unrestricted Extension Icon Upload
CVE-2026-4983
4.1 - Medium
- June 23, 2026
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or Content-Disposition: attachment. This allows an attacker to publish an extension with a malicious SVG icon and achieve stored cross-site scripting (XSS) when a user navigates directly to the icon URL. On deployments using local storage, script execution occurs within the Open VSX application origin, enabling session hijacking, authentication token theft, and unauthorized extension publishing. On deployments backed by external storage (such as open-vsx.org with an S3-backed CDN), execution is confined to the storage origin, reducing impact but still permitting phishing attacks and credential harvesting through attacker-crafted pages.
XSS
Eclipse Open VSX: Unauthorized Extension Uploads via Unisolated Build Scripts
CVE-2025-6705
5.3 - Medium
- June 27, 2025
A vulnerability in the Eclipse Open VSX Registrys automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the systems build scripts were executed without proper isolation, potentially exposing a privileged token. This token enabled the publishing of new extension versions under any namespace, including those not controlled by an attacker. However, it did not permit deletion of existing extensions, overwriting of published versions, or access to administrative features of the registry. The issue was reported on May 4, 2025, fully resolved by June 24, and followed by a comprehensive audit. No evidence of compromise was found, though 81 extensions were proactively deactivated as a precaution. The standard publishing process remained unaffected. Recommendations have been issued to mitigate similar risks in the future.
Improper Control of Dynamically-Managed Code Resources
OpenVSX 0.9.00.20.0: namespace API leaks privilege escalation
CVE-2025-1007
5.3 - Medium
- February 19, 2025
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Eclipse Open Vsx or by Eclipse? Click the Watch button to subscribe.