On open-vsx.org http://open-vsx.org/ it was possible to...
High severity
Unreviewed
Published
Jun 27, 2025
to the GitHub Advisory Database
•
Updated Jul 31, 2025
Description
Published by the National Vulnerability Database
Jun 27, 2025
Published to the GitHub Advisory Database
Jun 27, 2025
Last updated
Jul 31, 2025
On open-vsx.org http://open-vsx.org/ it was possible to run an arbitrary build scripts for auto-published extensions because of missing sandboxing of CI job runs. An attacker who had access to an existing extension could take over the service account of the marketplace. The issue has been fixed on June 24th, 2025 and the vulnerable code present in the publish-extension code repository.
References