CVE-2026-90882
- EPSS 0.44%
- Veröffentlicht 22.09.2026 09:27:34
- Zuletzt bearbeitet 22.09.2026 19:09:58
The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requ...
CVE-2025-12999
- EPSS 0.41%
- Veröffentlicht 21.09.2026 08:59:00
- Zuletzt bearbeitet 22.09.2026 14:17:11
UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a trusted proxy, fall...
CVE-2026-13323
- EPSS 0.21%
- Veröffentlicht 01.07.2026 11:28:20
- Zuletzt bearbeitet 06.07.2026 20:33:10
In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An unauthenticated attacker can regi...
CVE-2026-4983
- EPSS 0.22%
- Veröffentlicht 23.06.2026 10:50:38
- Zuletzt bearbeitet 24.06.2026 16:55:25
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or Content-Disposition: attachment. This allows an a...
CVE-2025-6705
- EPSS 0.23%
- Veröffentlicht 27.06.2025 14:57:06
- Zuletzt bearbeitet 31.07.2025 16:12:02
A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing a privileged t...
CVE-2025-1007
- EPSS 0.49%
- Veröffentlicht 19.02.2025 09:15:10
- Zuletzt bearbeitet 31.07.2025 12:44:45
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link...