« Volver al listado

Eclipse

Eclipse Open VSX: vulnerabilidades y CVE

Eclipse Open VSX tiene 6 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses4
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-90882Alta (8.7)0.44%—22 sept 2026
The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could…
CVE-2025-12999Crítica (9.1)0.34%—21 sept 2026
UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the…
CVE-2026-13323Alta (8.7)0.33%—1 jul 2026
In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An…
CVE-2026-4983Media (5.4)0.31%—23 jun 2026
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or…
CVE-2025-6705Alta (7.6)0.26%—27 jun 2025
A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation,…
CVE-2025-1007Media (6.9)0.52%—19 feb 2025
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name,…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1040 Network Sniffing1
  2. T1190 Exploit Public-Facing Application1
  3. T1195.002 Compromise Software Supply Chain1
  4. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Eclipse