API Misconfiguration in OpenVSX Affects Namespace Security
CVE-2025-1007
6.9MEDIUM
What is CVE-2025-1007?
In OpenVSX versions ranging from v0.9.0 to v0.20.0, a vulnerability exists in the /user/namespace/{namespace}/details API endpoint that permits unauthorized users to modify namespace details, including the name, description, website, support link, and social media links. Additionally, the /user/namespace/{namespace}/details/logo endpoint is affected, allowing users to change the logo without proper authorization. This security flaw raises serious concerns over the integrity and control of namespace data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OpenVSX 0.9.0 <= 0.20.0
OpenVSX 0.19.1
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdel Adim smaury Oisfi of Shielder
Andrea Cappa zi0Black of Aptos Labs
Leonardo Giovannini maitai
