Status: UPDATED | Advisory ID: CVE-2026-90882
| CVE | CVE-2026-90882 |
| CVSS Score / Version | 8.7 (High) / CVSS v4.0 |
| Updated | 2026-09-22 |
| Affected products | Eclipse Foundation open-vsx.org |
| Classified as | CWE-942 (Permissive Cross-domain Security Policy with Untrusted Domains) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Eclipse Foundation | open-vsx.org |
| Subsystems | General OT |
| Sectors | Multiple |
The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to the service in a logged-in user's browser and read the responses.
This exposed /user (login name, avatar, homepage, tokens URL), /user/tokens, /user/namespaces, /user/extensions, /user/search/{name} and /user/namespace/{name}/members, and — because /user/csrf was readable the same way — allowed the CSRF protection on write endpoints to be defeated. Chaining the two, an attacker page could call /user/token/create and exfiltrate a personal access token carrying publish and delete rights over the victim's namespaces.
The headers were emitted by the CDN/edge layer, not by the application: the Open VSX software sets allowCredentials(true) in exactly one place, against a single exact origin derived from ovsx.webui.url, and defines no CORS mapping on /user/ beyond it. No configuration of the software produces origin reflection with credentials. (NVD)
Monitor Eclipse Foundation's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-90882 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-90882 |