Skip to content
Open VSX Scanner Vulnerability Lets Malicious Extensions Go Live

Open VSX Scanner Vulnerability Lets Malicious Extensions Go Live

Gbhackers Mayura Kathir March 28, 2026

Open VSX, the extension marketplace used by VS Code forks such as Cursor and Windsurf, recently fixed a critical vulnerability in its newly introduced pre-publish scanning pipeline that could allow malicious extensions to bypass security checks and go live undetected. The issue, dubbed “Open Sesame,” stemmed from a fail-open condition in the scanning workflow. While […]

Extracted Entities

Companies (1)

Vulnerabilities (1)