By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Computing

Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks

News Room
Last updated: 2026/04/01 at 4:38 AM
News Room Published 1 April 2026
Share
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
SHARE

Ravie LakshmananMar 27, 2026Software Security / DevSecOps

Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX’s pre-publish scanning pipeline to cause the tool to allow a malicious Microsoft Visual Studio Code (VS Code) extension to pass the vetting process and go live in the registry.

“The pipeline had a single boolean return value that meant both ‘no scanners are configured’ and ‘all scanners failed to run,'” Koi Security researcher Oran Simhony said in a report shared with The Hacker News. “The caller couldn’t tell the difference. So when scanners failed under load, Open VSX treated it as ‘nothing to scan for’ and waved the extension right through.”

Early last month, the Eclipse Foundation, which maintains Open VSX, announced plans to enforce pre-publish security checks before VS Code extensions are published to the repository in an attempt to tackle the growing problem of malicious extensions.

With Open VSX also serving as the extension marketplace for Cursor, Windsurf, and other VS Code forks, the move was seen as a proactive approach to prevent rogue extensions from getting published in the first place. As part of pre-publish scanning, extensions that fail the process are quarantined for admin review.

The vulnerability discovered by Koi, codenamed Open Sesame, has to do with how this Java-based service reports the scan results. Specifically, it’s rooted in the fact that it misinterprets scanner job failures as no scanners are configured, causing an extension to be marked as passes, and then immediately activated and made available for download from Open VSX.

At the same time, it can also refer to a scenario where the scanners exist, and the scanner jobs have failed and cannot be enqueued because the database connection pool is exhausted. Even more troublingly, a recovery service designed to retry failed scans suffered from the same problem, thereby allowing extensions to skip the entire scanning process under certain conditions.

An attacker can take advantage of this weakness to flood the publish endpoint with several malicious .VSIX extensions, causing the concurrent load to exhaust the database connection pool. This, in turn, leads to a scenario where scan jobs fail to enqueue.

What’s notable about the attack is that it does not require any special privileges. A malicious actor with a free publisher account could have reliably triggered this vulnerability to undermine the scanning process and get their extension published. The issue was addressed in Open VSX version 0.32.0 last month following responsible disclosure on February 8, 2026.

“Pre-publish scanning is an important layer, but it’s one layer,” Koi said. “The pipeline’s design is sound, but a single boolean that couldn’t distinguish between ‘nothing to do’ and ‘something went wrong’ turned the entire infrastructure into a gate that opened under pressure.”

“This is a common anti-pattern: fail-open error handling hiding behind a code path designed for a legitimate ‘nothing to do’ case. If you’re building similar pipelines, make failure states explicit. Never let ‘no work needed’ and ‘work failed’ share a return value.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Today's NYT Mini Crossword Answers for April 1 – CNET Today's NYT Mini Crossword Answers for April 1 – CNET
Next Article Discord Open Sources Osprey Safety Rules Engine Processing 2.3 Million Rules per Second Discord Open Sources Osprey Safety Rules Engine Processing 2.3 Million Rules per Second
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Best Hisense deal: Save 8.03 on the Hisense 85-inch Class U8 Mini-LED ULED 4K TV at Amazon
Best Hisense deal: Save $798.03 on the Hisense 85-inch Class U8 Mini-LED ULED 4K TV at Amazon
News
Dell XPS 13 Snapdragon Elite Laptop Sees New EC Linux Driver To Improve Support
Dell XPS 13 Snapdragon Elite Laptop Sees New EC Linux Driver To Improve Support
Computing
PSA: Legacy AT&T unlimited plans face price hikes, and it’s a mess – 9to5Mac
PSA: Legacy AT&T unlimited plans face price hikes, and it’s a mess – 9to5Mac
News
Wrapping Your Car Keys With Aluminum Foil Could Help Stop Thieves – According To Science – BGR
Wrapping Your Car Keys With Aluminum Foil Could Help Stop Thieves – According To Science – BGR
News

You Might also Like

Dell XPS 13 Snapdragon Elite Laptop Sees New EC Linux Driver To Improve Support
Computing

Dell XPS 13 Snapdragon Elite Laptop Sees New EC Linux Driver To Improve Support

2 Min Read
Tech Odyssey Series: How Omniflow is rethinking streetlights with EV charging, connectivity, and clean energy · TechNode
Computing

Tech Odyssey Series: How Omniflow is rethinking streetlights with EV charging, connectivity, and clean energy · TechNode

7 Min Read
CBN gives banks 21 days to grade their cyber defences |
Computing

CBN gives banks 21 days to grade their cyber defences |

3 Min Read
How to Navigate Creator Burnout in 2023 (+ Free Report)
Computing

How to Navigate Creator Burnout in 2023 (+ Free Report)

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?