CVE-2025-1007: Eclipse Open Vsx

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.

Affected products

  • Eclipse Open Vsx: from 0.9.0, before 0.19.1 (fixed in 0.19.1)

Published 2025-02-19. Last modified 2026-06-17.