CVE Feed

    Dashboard / CVE / CVE-2025-1007

    CVE-2025-1007

    In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.

    Published:Feb 19, 2025
    Last Modified:Jul 31, 2025
    EPS:Feb 19, 2025
    EPSS Score:0.0007
    CVSS Score:5.3

    Affected Products

    Vendor
    Eclipse
    Product
    Open Vsx

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High