Open VSX Scanner Vulnerability Lets Malicious Extensions Go Live
ID: d2419017-d6bb-53ee-a226-c6c3776a9851
STIX ID: report--d2419017-d6bb-53ee-a226-c6c3776a9851
Feed Name: GBHackers
Threat Score
Open VSX fixed a critical ‘Open Sesame’ vulnerability in its pre-publish scanning pipeline that could be triggered by exhausting backend resources, causing scanner job failures to be misinterpreted as ‘no scanners configured’ and allowing malicious extensions to be published with a false “PASSED” status; the issue was responsibly disclosed on February 8, 2026 and patched within three days on February 11.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
