BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Open VSX Bug Let Malicious Extensions Bypass Scans

  • A critical security flaw in the Open VSX registry’s scanning pipeline could have allowed malicious extensions to bypass vetting checks.
  • The bug, named Open Sesame, misinterpreted scanner failures as no scanners being configured, automatically approving dangerous extensions.
  • Attackers could have exploited this with a free account by flooding the system to exhaust database connections and skip scanning.
  • The vulnerability was responsibly disclosed and patched in Open VSX version 0.32.0, released in February 2026.

Cybersecurity researchers revealed on March 27, 2026, that a now-patched bug in the Open VSX extension marketplace’s security pipeline could have let malicious Visual Studio Code add-ons slip through undetected. According to a report shared with The Hacker News, the flaw stemmed from a critical misinterpretation of scanner job failures.

- Advertisement -

The vulnerability, codenamed Open Sesame, originated from a single boolean return value that conflated two distinct states. “The pipeline had a single boolean return value that meant both ‘no scanners are configured’ and ‘all scanners failed to run,'” researcher Oran Simhony said. Consequently, the system would mistakenly wave extensions through when scanners failed under load, treating it as if there was nothing to scan.

This presented a severe risk as Open VSX also serves extensions for other popular code editors like Cursor and Windsurf. An attacker could exploit the weakness by flooding the publish endpoint with malicious extensions to exhaust the database connection pool, data shows. This attack would cause scan jobs to fail to enqueue, bypassing the newly introduced pre-publish security checks the Eclipse Foundation had announced.

The issue was addressed following responsible disclosure on February 8, 2026. The fix was implemented in Open VSX version 0.32.0 last month, as detailed in a GitHub commit. Koi Security emphasized this was a common anti-pattern in system design, reports indicate.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Major Mining Pools Join Stratum V2 to Boost Bitcoin Efficiency

Seven leading mining pools, including the largest Foundry and AntPool, have joined the Stratum...

CLARITY Act Could Boost U.S. Crypto Market Share, Advocate Says

The CLARITY Act aims to bring crypto firms back to the U.S. by establishing...

Banking Lobby Battles Stablecoin Bill Over Deposit Fears

Major U.S. banking associations are lobbying the Senate to tighten stablecoin legislation, warning current...

Bitcoin Rockets 30% As Dalio Warns Of Dollar Collapse

Bitcoin's price bounced 30% after geopolitical shocks, but remains far from peak. The U.S. dollar...

Bitcoin Bear Bottom? Key Index Signals 90% Probability

Checkonchain's Mean Reversion Index hit a Q10 reading, historically a 90% probability bottom signal...

Must Read

Crypto in New York: The 2026 Guide to Legal Exchanges and BitLicense Regulations

TL;DR: Trading crypto in New York is legal but heavily regulated by the New York Department of Financial Services (NYDFS). Platforms must hold a BitLicense...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading