Arbitrary Code Execution Vulnerability in Open-VSX Marketplace Extensions
CVE-2025-6705
7.6HIGH
What is CVE-2025-6705?
An issue in the Open-VSX marketplace allowed arbitrary build scripts to be executed for auto-published extensions due to a lack of proper sandboxing during CI job execution. This vulnerability enabled an attacker with access to an existing extension to potentially hijack the service account associated with the marketplace. The issue was addressed on June 24, 2025, after identifying and rectifying the vulnerable portions of the publish-extension code repository.
Affected Version(s)
Eclipse Open VSX date < 20250624