Vulnerabilities · 172 days ago
That logic error allowed malicious Visual Studio Code extensions to be activated and downloaded without review.
1 source covering this story
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Open VSX bug misread scanner failures as clean results, letting malicious VS Code extensions go live before patch in v0.32.0.
Part of the PlainSec briefing for 2026-03-28