CVE-2026-13323
Eclipse Foundation Eclipse Open VSX, open vsx
In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An unauthenticated attacker can register a publisher account, upload a VSIX containing a crafted HTML payload, and induce an authenticated user to visit the resulting URL. The browser renders the file inline in the open-vsx.org origin context, enabling session token exfiltration, persistent Personal Access Token (PAT) generation, and unauthorized publication of malicious extension...
- CVSS
- 8.7
- EPSS
- 0.21% 11.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.01