Eclipse
Eclipse Open VSX: vulnerabilities and CVEs
Eclipse Open VSX has 6 published vulnerabilities, 4 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months4
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90882 | High (8.7) | 0.44% | — | Sep 22, 2026 | The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could… |
| CVE-2025-12999 | Critical (9.1) | 0.34% | — | Sep 21, 2026 | UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the… |
| CVE-2026-13323 | High (8.7) | 0.33% | — | Jul 1, 2026 | In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An… |
| CVE-2026-4983 | Medium (5.4) | 0.31% | — | Jun 23, 2026 | Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or… |
| CVE-2025-6705 | High (7.6) | 0.26% | — | Jun 27, 2025 | A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation,… |
| CVE-2025-1007 | Medium (6.9) | 0.52% | — | Feb 19, 2025 | In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name,… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.