logo

Open VSX Scanner Vulnerability Lets Malicious Extensions Go Live

ID: d2419017-d6bb-53ee-a226-c6c3776a9851

STIX ID: report--d2419017-d6bb-53ee-a226-c6c3776a9851

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-03-28

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Open VSX fixed a critical ‘Open Sesame’ vulnerability in its pre-publish scanning pipeline that could be triggered by exhausting backend resources, causing scanner job failures to be misinterpreted as ‘no scanners configured’ and allowing malicious extensions to be published with a false “PASSED” status; the issue was responsibly disclosed on February 8, 2026 and patched within three days on February 11.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.