Skip to main content

Vendor/product archive

eclipse / open_vsx CVEs

Beta · best-effort

4 CVEs tagged to eclipse / open_vsx0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-13323

Published Jul 1, 2026

In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Dispos…

CVSS 4.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-4983

Published Jun 23, 2026

Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Conte…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6705

Published Jun 27, 2025

A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1007

Published Feb 19, 2025

In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Cont…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1