Skip to main content

CVE-2026-90882: CWE-942 in Eclipse Foundation open-vsx.org

0
High
VulnerabilityCVE-2026-90882cvecve-2026-90882cwe-942
Published: 09/22/2026 (09/22/2026, 09:27:34 UTC)
Source: CVE Database V5
Vendor/Project: Eclipse Foundation
Product: open-vsx.org

Description

The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to the service in a logged-in user's browser and read the responses. This exposed /user (login name, avatar, homepage, tokens URL), /user/tokens, /user/namespaces, /user/extensions, /user/search/{name} and /user/namespace/{name}/members, and — because /user/csrf was readable the same way — allowed the CSRF protection on write endpoints to be defeated. Chaining the two, an attacker page could call /user/token/create and exfiltrate a personal access token carrying publish and delete rights over the victim's namespaces. The headers were emitted by the CDN/edge layer, not by the application: the Open VSX software sets allowCredentials(true) in exactly one place, against a single exact origin derived from ovsx.webui.url, and defines no CORS mapping on /user/ beyond it. No configuration of the software produces origin reflection with credentials.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Passive
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

Eclipse Foundation

open-vsx.org

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 13:47:38 UTC

Technical Analysis

The open-vsx.org service improperly configures CORS headers at the CDN/edge layer, reflecting the origin in Access-Control-Allow-Origin while setting Access-Control-Allow-Credentials to true on authenticated /user/ endpoints. This allows cross-origin credentialed requests to access sensitive user information and tokens. The vulnerability exposes multiple user-related endpoints and defeats CSRF protections by making the /user/csrf endpoint readable cross-origin. An attacker can chain these flaws to create and steal personal access tokens with elevated privileges. The Open VSX software itself does not produce this origin reflection; it is caused by the CDN/edge configuration. No official fix or patch is documented in the provided data.

Potential Impact

An attacker can exploit this vulnerability to perform cross-origin credentialed requests from any webpage, accessing sensitive user data such as login names, avatars, tokens, namespaces, and extensions. The attacker can also bypass CSRF protections and create personal access tokens with publish and delete rights on the victim's namespaces, potentially leading to unauthorized code publishing or deletion. This compromises user account integrity and confidentiality.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the issue originates from the CDN/edge layer configuration rather than the application, remediation likely involves correcting CORS header settings at the CDN or edge proxy. Until an official fix is available, restricting or disabling credentialed cross-origin requests on the affected endpoints may mitigate risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
eclipse
Date Reserved
2026-09-14T07:44:22.377Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab283a2f7a7c54106397407

Added to database: 09/22/2026, 13:33:22 UTC

Last enriched: 09/22/2026, 13:47:38 UTC

Last updated: 09/23/2026, 01:58:07 UTC

Views: 36

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses