Executive brief
Eclipse Open VSX is an open-source registry for VS Code extensions. A vulnerability allows attackers to upload malicious extension icons that can execute scripts in a user's browser. Depending on how the registry is hosted, this could lead to session hijacking, theft of authentication tokens, or phishing attacks against developers using the platform.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Eclipse Open VSX due to improper neutralization of SVG files uploaded as extension icons. The application fails to sanitize these files and serves them with the 'image/svg+xml' content type without protective security headers like Content-Security-Policy or Content-Disposition: attachment. An attacker with extension publishing privileges can upload a malicious SVG containing embedded scripts. When a victim navigates directly to the icon's URL, the script executes. In local storage configurations, this occurs within the application's origin, potentially allowing for session hijacking and unauthorized publishing; in CDN-backed configurations, the impact is limited to the storage origin. The issue is fixed in version 0.34.1 by rejecting SVG icons by default.
Affected products
- Eclipse Foundation Eclipse Open VSX 0.1.0 to 0.34.1
Timeline
- 2026-06-23: disclosed
- 2026-06-23: advisory
- 2026-06-23: patched: Fixed in version 0.34.1