Vulnerabilities & Exploits · Supply Chain

Open VSX Bug Lets Malicious VS Code Extensions Bypass Pre-Publish Checks

A logic error in Open VSX's scan pipeline misclassified scanner failures as 'no scanners configured', allowing malicious Visual Studio Code extensions to pass pre-publish security checks and go live. The issue affected Open VSX-powered marketplaces and was fixed in v0.32.0.

1 source · Mar 27

Timeline

Sources

Part of the PlainSec briefing for 2026-03-27

Every edition of this story: Open VSX Bug Lets Malicious VS Code Extensions Bypass Pre-Publish Checks

More from today