CVE-2026-90882: CWE-942 in Eclipse Foundation open-vsx.org
The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to the service in a logged-in user's browser and read the responses. This exposed /user (login name, avatar, homepage, tokens URL), /user/tokens, /user/namespaces, /user/extensions, /user/search/{name} and /user/namespace/{name}/members, and — because /user/csrf was readable the same way — allowed the CSRF protection on write endpoints to be defeated. Chaining the two, an attacker page could call /user/token/create and exfiltrate a personal access token carrying publish and delete rights over the victim's namespaces. The headers were emitted by the CDN/edge layer, not by the application: the Open VSX software sets allowCredentials(true) in exactly one place, against a single exact origin derived from ovsx.webui.url, and defines no CORS mapping on /user/ beyond it. No configuration of the software produces origin reflection with credentials.
AI Analysis
Technical Summary
The open-vsx.org service improperly configures CORS headers at the CDN/edge layer, reflecting the origin in Access-Control-Allow-Origin while setting Access-Control-Allow-Credentials to true on authenticated /user/ endpoints. This allows cross-origin credentialed requests to access sensitive user information and tokens. The vulnerability exposes multiple user-related endpoints and defeats CSRF protections by making the /user/csrf endpoint readable cross-origin. An attacker can chain these flaws to create and steal personal access tokens with elevated privileges. The Open VSX software itself does not produce this origin reflection; it is caused by the CDN/edge configuration. No official fix or patch is documented in the provided data.
Potential Impact
An attacker can exploit this vulnerability to perform cross-origin credentialed requests from any webpage, accessing sensitive user data such as login names, avatars, tokens, namespaces, and extensions. The attacker can also bypass CSRF protections and create personal access tokens with publish and delete rights on the victim's namespaces, potentially leading to unauthorized code publishing or deletion. This compromises user account integrity and confidentiality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the issue originates from the CDN/edge layer configuration rather than the application, remediation likely involves correcting CORS header settings at the CDN or edge proxy. Until an official fix is available, restricting or disabling credentialed cross-origin requests on the affected endpoints may mitigate risk.
CVE-2026-90882: CWE-942 in Eclipse Foundation open-vsx.org
Description
The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to the service in a logged-in user's browser and read the responses. This exposed /user (login name, avatar, homepage, tokens URL), /user/tokens, /user/namespaces, /user/extensions, /user/search/{name} and /user/namespace/{name}/members, and — because /user/csrf was readable the same way — allowed the CSRF protection on write endpoints to be defeated. Chaining the two, an attacker page could call /user/token/create and exfiltrate a personal access token carrying publish and delete rights over the victim's namespaces. The headers were emitted by the CDN/edge layer, not by the application: the Open VSX software sets allowCredentials(true) in exactly one place, against a single exact origin derived from ovsx.webui.url, and defines no CORS mapping on /user/ beyond it. No configuration of the software produces origin reflection with credentials.
CVSS v4.0
Score 8.7high
Affected software
Eclipse Foundation
open-vsx.org
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The open-vsx.org service improperly configures CORS headers at the CDN/edge layer, reflecting the origin in Access-Control-Allow-Origin while setting Access-Control-Allow-Credentials to true on authenticated /user/ endpoints. This allows cross-origin credentialed requests to access sensitive user information and tokens. The vulnerability exposes multiple user-related endpoints and defeats CSRF protections by making the /user/csrf endpoint readable cross-origin. An attacker can chain these flaws to create and steal personal access tokens with elevated privileges. The Open VSX software itself does not produce this origin reflection; it is caused by the CDN/edge configuration. No official fix or patch is documented in the provided data.
Potential Impact
An attacker can exploit this vulnerability to perform cross-origin credentialed requests from any webpage, accessing sensitive user data such as login names, avatars, tokens, namespaces, and extensions. The attacker can also bypass CSRF protections and create personal access tokens with publish and delete rights on the victim's namespaces, potentially leading to unauthorized code publishing or deletion. This compromises user account integrity and confidentiality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the issue originates from the CDN/edge layer configuration rather than the application, remediation likely involves correcting CORS header settings at the CDN or edge proxy. Until an official fix is available, restricting or disabling credentialed cross-origin requests on the affected endpoints may mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- eclipse
- Date Reserved
- 2026-09-14T07:44:22.377Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab283a2f7a7c54106397407
Added to database: 09/22/2026, 13:33:22 UTC
Last enriched: 09/22/2026, 13:47:38 UTC
Last updated: 09/23/2026, 01:58:07 UTC
Views: 36
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.