BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Open VSX Bug Let Malicious Extensions Bypass Scans

  • A critical security flaw in the Open VSX registry’s scanning pipeline could have allowed malicious extensions to bypass vetting checks.
  • The bug, named Open Sesame, misinterpreted scanner failures as no scanners being configured, automatically approving dangerous extensions.
  • Attackers could have exploited this with a free account by flooding the system to exhaust database connections and skip scanning.
  • The vulnerability was responsibly disclosed and patched in Open VSX version 0.32.0, released in February 2026.

Cybersecurity researchers revealed on March 27, 2026, that a now-patched bug in the Open VSX extension marketplace’s security pipeline could have let malicious Visual Studio Code add-ons slip through undetected. According to a report shared with The Hacker News, the flaw stemmed from a critical misinterpretation of scanner job failures.

- Advertisement -

The vulnerability, codenamed Open Sesame, originated from a single boolean return value that conflated two distinct states. “The pipeline had a single boolean return value that meant both ‘no scanners are configured’ and ‘all scanners failed to run,'” researcher Oran Simhony said. Consequently, the system would mistakenly wave extensions through when scanners failed under load, treating it as if there was nothing to scan.

This presented a severe risk as Open VSX also serves extensions for other popular code editors like Cursor and Windsurf. An attacker could exploit the weakness by flooding the publish endpoint with malicious extensions to exhaust the database connection pool, data shows. This attack would cause scan jobs to fail to enqueue, bypassing the newly introduced pre-publish security checks the Eclipse Foundation had announced.

The issue was addressed following responsible disclosure on February 8, 2026. The fix was implemented in Open VSX version 0.32.0 last month, as detailed in a GitHub commit. Koi Security emphasized this was a common anti-pattern in system design, reports indicate.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

RaveDAO Denies Manipulation as Exchanges Probe Token Plunge

RaveDAO has denied responsibility for its RAVE token's extreme price volatility following allegations of...

Robinhood Soars 31% on SEC Rule Change and Crypto Rally

Robinhood (HOOD) stock surged 31% this week, making it the top performer in the...

Bitcoin Eyes $82K by April’s End Amid Volatility

Analysts predict a final push for Bitcoin towards the $78,000-$80,000 zone before a potential...

Worldcoin Drops 13% Despite Zoom, Docusign ID Deals

Worldcoin (WLD) dropped 13.4% to roughly $0.28 on Friday, contrasting with a broader crypto...

Bitcoin Soars Past Key Resistance; Traders See 69% Chance of $84K

Bitcoin surged 2.7%, breaking a key descending resistance line that had suppressed its price...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading