CVE-2025-1007: Improper Authorization in /user/namespace/{namespace}/details
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1007?
CVE-2025-1007 is classified as a medium severity vulnerability due to unauthorized access to namespace details.
How do I fix CVE-2025-1007?
To fix CVE-2025-1007, upgrade your OpenVSX instance to a version later than v0.20.0.
What versions of OpenVSX are affected by CVE-2025-1007?
OpenVSX versions from v0.9.0 to v0.20.0 are affected by CVE-2025-1007.
What type of data can be edited due to CVE-2025-1007?
CVE-2025-1007 allows unauthorized users to edit namespace details, including name, description, website, support link, and social media links.
Who can be impacted by CVE-2025-1007?
Users who rely on namespace security and ownership in OpenVSX can be impacted by CVE-2025-1007 due to unauthorized changes.