CVE-2025-1007 Details
Description
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.
A vulnerability exists in OpenVSX versions 0.9.0 through 0.20.0, allowing users to edit namespace details via the '/user/namespace/{namespace}/details' API, regardless of their ownership or contribution status. Affected details include the namespace name, description, website, support link, and social media links. The vulnerability also extends to the '/user/namespace/{namespace}/details/logo' endpoint, where users could change the namespace logo without proper authorization.
Users can update to OpenVSX version 0.19.1, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/eclipse/openvsx/security/advisories/GHSA-wc7c-xq2f-qp4h | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-283 | Unverified Ownership | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| eclipse open vsx | >= 0.9.0, < 0.19.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | Initial Analysis | [email protected] |
| Feb 19, 2025 | New CVE Received | [email protected] |