Vulnerabilities & Exploits · Supply Chain

Open VSX Bug Lets Malicious VS Code Extensions Bypass Pre-Publish Checks

That logic error allowed malicious Visual Studio Code extensions to be activated and downloaded without review.

1 source · Mar 27

Timeline

Sources

Part of the PlainSec briefing for 2026-03-28

Every edition of this story: Open VSX Bug Lets Malicious VS Code Extensions Bypass Pre-Publish Checks

More from today