logo

Open VSX’s New Scanner Vulnerability Allows Malicious Extension Goes Live

ID: b56e8de9-8d38-579a-a9a7-f73ad9395fb1

STIX ID: report--b56e8de9-8d38-579a-a9a7-f73ad9395fb1

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A "fail-open" vulnerability named "Open Sesame" in the Open VSX extension marketplace allowed malicious .vsix packages to bypass the platform's pre-publish security scanners because a boolean return value could not distinguish between ‘no scanners configured’ and ‘scanner job failures’; an attacker could trigger the condition by flooding the publish endpoint to exhaust database connections. The flaw affected both the primary scanning submission logic and the recovery service, required no privileged access, was reported on Feb 8, 2026, and was fixed by the Open VSX team on Feb 11, 2026; users who installed extensions during the vulnerable window are advised to review them.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.