CVE-2025-1007: Eclipse Open Vsx
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.
Affected products
- Eclipse Open Vsx: from 0.9.0, before 0.19.1 (fixed in 0.19.1)
Published 2025-02-19. Last modified 2026-06-17.