Vulnerabilità ed exploit · Supply chain
La causa è un errore di logica che ha interpretato i fallimenti dei job di scanner come 'no scanners configured'. Il problema interessava anche il servizio di recovery e è stato corretto in v0.32.0.
1 fonte · 27 mar
The Hacker News
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Open VSX bug misread scanner failures as clean results, letting malicious VS Code extensions go live before patch in v0.32.0.
originalePart of the PlainSec briefing for 2026-03-27
Every edition of this story: Bug Open VSX Permette Estensioni VS Code Maligne Pubblicate