BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Open VSX Bug Let Malicious Extensions Bypass Scans

  • A critical security flaw in the Open VSX registry’s scanning pipeline could have allowed malicious extensions to bypass vetting checks.
  • The bug, named Open Sesame, misinterpreted scanner failures as no scanners being configured, automatically approving dangerous extensions.
  • Attackers could have exploited this with a free account by flooding the system to exhaust database connections and skip scanning.
  • The vulnerability was responsibly disclosed and patched in Open VSX version 0.32.0, released in February 2026.

Cybersecurity researchers revealed on March 27, 2026, that a now-patched bug in the Open VSX extension marketplace’s security pipeline could have let malicious Visual Studio Code add-ons slip through undetected. According to a report shared with The Hacker News, the flaw stemmed from a critical misinterpretation of scanner job failures.

- Advertisement -

The vulnerability, codenamed Open Sesame, originated from a single boolean return value that conflated two distinct states. “The pipeline had a single boolean return value that meant both ‘no scanners are configured’ and ‘all scanners failed to run,'” researcher Oran Simhony said. Consequently, the system would mistakenly wave extensions through when scanners failed under load, treating it as if there was nothing to scan.

This presented a severe risk as Open VSX also serves extensions for other popular code editors like Cursor and Windsurf. An attacker could exploit the weakness by flooding the publish endpoint with malicious extensions to exhaust the database connection pool, data shows. This attack would cause scan jobs to fail to enqueue, bypassing the newly introduced pre-publish security checks the Eclipse Foundation had announced.

The issue was addressed following responsible disclosure on February 8, 2026. The fix was implemented in Open VSX version 0.32.0 last month, as detailed in a GitHub commit. Koi Security emphasized this was a common anti-pattern in system design, reports indicate.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Salesforce disables Klue app after data breach

Security firm Klue suffered a breach via a legacy credential, allowing hackers to steal...

Yuan Gains in Africa as $400 Billion Trade Shifts From Dollar

The Chinese yuan is gaining significant ground in African trade settlements, challenging the US...

BlackRock’s Bitcoin ETF Lures New Investors to Entire ETF Market

BlackRock's spot Bitcoin ETF has attracted a significant number of first-time ETF investors.Many of...

Audit Gap Exposed As AI Finds Major Four-Year Crypto Bug

A critical four-year-old bug in ZCash's shielded pool, discovered in June 2026, wiped out...

Z.ai’s GLM-5.2 Nears Claude Opus, Beats GPT-5.5, MIT Licensed

Z.ai released the GLM-5.2 AI model, which performs within 1% of Claude Opus 4.8...

Must Read

17 Best Cryptocurrency Wallets

If you are looking for a list with the best cryptocurrency wallets, then you've landed on the right page. Cryptocurrency, as we all know,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading