Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
ID: 36e3447a-19f8-5bc1-9099-1af510184402
STIX ID: report--36e3447a-19f8-5bc1-9099-1af510184402
Feed Name: The Hacker News
Threat Score
Cybersecurity researchers disclosed a patched vulnerability in Open VSX's pre-publish scanning pipeline ("Open Sesame") where a single-boolean return value caused scanner job failures to be treated as "nothing to scan", allowing malicious VS Code extensions to bypass vetting and be published. An attacker could trigger this by flooding the publish endpoint to exhaust the database connection pool; the issue was responsibly disclosed and addressed in Open VSX v0.32.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
