Openvsx · Openvsx · CVE-2025-12999
**Name of the Vulnerable Software and Affected Versions**
Open VSX (affected versions not specified)
**Description**
An unauthenticated remote attacker can poison the per-extension metadata cache by supplying crafted `X-Forwarded-Host`, `X-Forwarded-Proto`, and `X-Forwarded-Prefix` request headers. The `UrlUtil.getBaseUrl()` function builds absolute URLs for download links, icons, assets, and API URLs using these headers without verifying if the sender is a trusted proxy. Because responses are cached using keys that do not include the host, a single forged request can inject attacker-controlled URLs into entries served to all other clients. This allows an attacker to supply a malicious VSIX package along with its own signature and public key, leading VS Code-compatible editors to install malicious software. This issue affects servers reachable directly by clients or those behind proxies that relay rather than overwrite these headers.
**Recommendations**
Configure the reverse proxy to set instead of relay the `X-Forwarded-Host`, `X-Forwarded-Proto`, and `X-Forwarded-Prefix` headers.
Ensure the server is only reachable through the configured proxy.
Flush the caches after applying configuration changes to remove poisoned entries.