PT-2026-54628 · Anysphere+4 · Cursor+4
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Open VSX Registry versions prior to 1.0.2
Description
The '/vscode/unpkg/' endpoint serves user-supplied HTML files with a
text/html Content-Type and lacks a Content-Security-Policy or Content-Disposition: attachment response header. This allows an unauthenticated attacker to register a publisher account and upload a VSIX file containing a crafted HTML payload. If an authenticated user is induced to visit the resulting URL, the browser renders the file inline within the open-vsx.org origin context. This can lead to session token exfiltration, the generation of persistent Personal Access Tokens (PAT), and the unauthorized publication of malicious extension versions. Since extensions are distributed to editors such as VS Code, VSCodium, Cursor, and Windsurf, this issue could facilitate a supply chain attack against downstream users.Recommendations
Update Open VSX Registry to version 1.0.2 or later.
Restrict access to the '/vscode/unpkg/' endpoint as a temporary mitigation measure.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cursor
Open Vsx Registry
Vscode
Vscodium
Windsurf