By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Computing

Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks

News Room
Last updated: 2026/04/01 at 4:38 AM
News Room Published 1 April 2026
Share
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
SHARE

Ravie LakshmananMar 27, 2026Software Security / DevSecOps

Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX’s pre-publish scanning pipeline to cause the tool to allow a malicious Microsoft Visual Studio Code (VS Code) extension to pass the vetting process and go live in the registry.

“The pipeline had a single boolean return value that meant both ‘no scanners are configured’ and ‘all scanners failed to run,'” Koi Security researcher Oran Simhony said in a report shared with The Hacker News. “The caller couldn’t tell the difference. So when scanners failed under load, Open VSX treated it as ‘nothing to scan for’ and waved the extension right through.”

Early last month, the Eclipse Foundation, which maintains Open VSX, announced plans to enforce pre-publish security checks before VS Code extensions are published to the repository in an attempt to tackle the growing problem of malicious extensions.

With Open VSX also serving as the extension marketplace for Cursor, Windsurf, and other VS Code forks, the move was seen as a proactive approach to prevent rogue extensions from getting published in the first place. As part of pre-publish scanning, extensions that fail the process are quarantined for admin review.

The vulnerability discovered by Koi, codenamed Open Sesame, has to do with how this Java-based service reports the scan results. Specifically, it’s rooted in the fact that it misinterprets scanner job failures as no scanners are configured, causing an extension to be marked as passes, and then immediately activated and made available for download from Open VSX.

At the same time, it can also refer to a scenario where the scanners exist, and the scanner jobs have failed and cannot be enqueued because the database connection pool is exhausted. Even more troublingly, a recovery service designed to retry failed scans suffered from the same problem, thereby allowing extensions to skip the entire scanning process under certain conditions.

An attacker can take advantage of this weakness to flood the publish endpoint with several malicious .VSIX extensions, causing the concurrent load to exhaust the database connection pool. This, in turn, leads to a scenario where scan jobs fail to enqueue.

What’s notable about the attack is that it does not require any special privileges. A malicious actor with a free publisher account could have reliably triggered this vulnerability to undermine the scanning process and get their extension published. The issue was addressed in Open VSX version 0.32.0 last month following responsible disclosure on February 8, 2026.

“Pre-publish scanning is an important layer, but it’s one layer,” Koi said. “The pipeline’s design is sound, but a single boolean that couldn’t distinguish between ‘nothing to do’ and ‘something went wrong’ turned the entire infrastructure into a gate that opened under pressure.”

“This is a common anti-pattern: fail-open error handling hiding behind a code path designed for a legitimate ‘nothing to do’ case. If you’re building similar pipelines, make failure states explicit. Never let ‘no work needed’ and ‘work failed’ share a return value.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Today's NYT Mini Crossword Answers for April 1 – CNET Today's NYT Mini Crossword Answers for April 1 – CNET
Next Article Discord Open Sources Osprey Safety Rules Engine Processing 2.3 Million Rules per Second Discord Open Sources Osprey Safety Rules Engine Processing 2.3 Million Rules per Second
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
Computing
Toyota’s Woven Capital appoints new CIO and COO in push for finding the ‘future of mobility’ |  News
Toyota’s Woven Capital appoints new CIO and COO in push for finding the ‘future of mobility’ | News
News
The Best Tablets We’ve Tested for 2026
The Best Tablets We’ve Tested for 2026
News
One of Apple’s First Employees Looks Back at 50 Years
Software

You Might also Like

AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
Computing

AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion

3 Min Read
Rec Room shutting down: Once valued at .5B, social gaming platform finds profits elusive
Computing

Rec Room shutting down: Once valued at $3.5B, social gaming platform finds profits elusive

5 Min Read
MediaTek MT7927 “Filogic 380” WiFi Support Coming Together For Linux
Computing

MediaTek MT7927 “Filogic 380” WiFi Support Coming Together For Linux

1 Min Read
JD.com and Unitree to open first offline store in Beijing, offering hands-on robot experience and on-site orders · TechNode
Computing

JD.com and Unitree to open first offline store in Beijing, offering hands-on robot experience and on-site orders · TechNode

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?