BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Open VSX Bug Let Malicious Extensions Bypass Scans

  • A critical security flaw in the Open VSX registry’s scanning pipeline could have allowed malicious extensions to bypass vetting checks.
  • The bug, named Open Sesame, misinterpreted scanner failures as no scanners being configured, automatically approving dangerous extensions.
  • Attackers could have exploited this with a free account by flooding the system to exhaust database connections and skip scanning.
  • The vulnerability was responsibly disclosed and patched in Open VSX version 0.32.0, released in February 2026.

Cybersecurity researchers revealed on March 27, 2026, that a now-patched bug in the Open VSX extension marketplace’s security pipeline could have let malicious Visual Studio Code add-ons slip through undetected. According to a report shared with The Hacker News, the flaw stemmed from a critical misinterpretation of scanner job failures.

- Advertisement -

The vulnerability, codenamed Open Sesame, originated from a single boolean return value that conflated two distinct states. “The pipeline had a single boolean return value that meant both ‘no scanners are configured’ and ‘all scanners failed to run,'” researcher Oran Simhony said. Consequently, the system would mistakenly wave extensions through when scanners failed under load, treating it as if there was nothing to scan.

This presented a severe risk as Open VSX also serves extensions for other popular code editors like Cursor and Windsurf. An attacker could exploit the weakness by flooding the publish endpoint with malicious extensions to exhaust the database connection pool, data shows. This attack would cause scan jobs to fail to enqueue, bypassing the newly introduced pre-publish security checks the Eclipse Foundation had announced.

The issue was addressed following responsible disclosure on February 8, 2026. The fix was implemented in Open VSX version 0.32.0 last month, as detailed in a GitHub commit. Koi Security emphasized this was a common anti-pattern in system design, reports indicate.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bipartisan Crypto Tax Bill Introduced in House

A bipartisan bill, the PARITY Act, was introduced to modernize digital asset tax rules...

Space Force Awards SpaceX $4.16B for Target-Tracking Satellites

SpaceX secured a $4.16 billion Space Force contract for a satellite-based target tracking network.This...

U.S. Approves First Bitcoin Perpetual Futures

The U.S. Commodity Futures Trading Commission (CFTC) approved the nation's first regulated Bitcoin perpetual...

Arabic NLP Research Gains EdgeCloud GPU Support

Researchers at Cairo University leveraged distributed GPU compute via Theta EdgeCloud to overcome infrastructure...

Bitcoin Buy Orders Stack $500M Near Key $70K Zone

More than $500 million in buy orders is clustered between $72,000 and $70,000, creating...

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading