« Back to list

Eclipse

Eclipse Open VSX: vulnerabilities and CVEs

Eclipse Open VSX has 6 published vulnerabilities, 4 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months4
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-90882High (8.7)0.44%—Sep 22, 2026
The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could…
CVE-2025-12999Critical (9.1)0.34%—Sep 21, 2026
UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the…
CVE-2026-13323High (8.7)0.33%—Jul 1, 2026
In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An…
CVE-2026-4983Medium (5.4)0.31%—Jun 23, 2026
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or…
CVE-2025-6705High (7.6)0.26%—Jun 27, 2025
A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation,…
CVE-2025-1007Medium (6.9)0.52%—Feb 19, 2025
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name,…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1040 Network Sniffing1
  2. T1190 Exploit Public-Facing Application1
  3. T1195.002 Compromise Software Supply Chain1
  4. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Eclipse