← All Advisories

CVE-2026-90882

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-90882

Key Details

CVECVE-2026-90882
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-09-22
Affected productsEclipse Foundation open-vsx.org
Classified asCWE-942 (Permissive Cross-domain Security Policy with Untrusted Domains)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Eclipse Foundationopen-vsx.org
SubsystemsGeneral OT
SectorsMultiple

What to Know

The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to the service in a logged-in user's browser and read the responses.

This exposed /user (login name, avatar, homepage, tokens URL), /user/tokens, /user/namespaces, /user/extensions, /user/search/{name} and /user/namespace/{name}/members, and — because /user/csrf was readable the same way — allowed the CSRF protection on write endpoints to be defeated. Chaining the two, an attacker page could call /user/token/create and exfiltrate a personal access token carrying publish and delete rights over the victim's namespaces.

The headers were emitted by the CDN/edge layer, not by the application: the Open VSX software sets allowCredentials(true) in exactly one place, against a single exact origin derived from ovsx.webui.url, and defines no CORS mapping on /user/ beyond it. No configuration of the software produces origin reflection with credentials. (NVD)

What to Do

Monitor Eclipse Foundation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-90882
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-90882