CVE-2025-6705: High severity Eclipse Open VSX Registry vulnerability

Published Jun 27, 2025
·
Updated

A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing a privileged token. This token enabled the publishing of new extension versions under any namespace, including those not controlled by an attacker. However, it did not permit deletion of existing extensions, overwriting of published versions, or access to administrative features of the registry.

The issue was reported on May 4, 2025, fully resolved by June 24, and followed by a comprehensive audit. No evidence of compromise was found, though 81 extensions were proactively deactivated as a precaution. The standard publishing process remained unaffected. Recommendations have been issued to mitigate similar risks in the future.

Affected Software

2 affected components
Eclipse Open VSX Registry
Eclipse Open VSX

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Because the automated publishing build scripts were executed without proper isolation and potentially exposed a privileged token, ensure the publishing/build scripts run in properly isolated execution environments to prevent token exposure (e.g., isolate build execution and restrict token access to only what is required during publishing).

  2. Operational

    Proactively deactivate extensions affected by (or potentially related to) the automated publishing risk; the incident response deactivated 81 extensions as a precaution.

  3. Operational

    After the comprehensive audit (reported May 4, 2025 and resolved June 24, 2025), verify token and publishing credentials are still valid for the registry publishing pipeline and rotate/recreate any privileged tokens that may have been exposed, since the token could publish new extension versions under any namespace.

Event History

Jun 27, 2025
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-6705?

CVE-2025-6705 is considered to have a critical severity due to the potential for unauthorized users to execute arbitrary scripts.

2

How do I fix CVE-2025-6705?

To fix CVE-2025-6705, ensure that you are using the updated version of Open VSX where the sandboxing issue has been addressed.

3

What vulnerabilities does CVE-2025-6705 exploit?

CVE-2025-6705 exploits the lack of sandboxing in CI job runs, allowing arbitrary build scripts to be executed.

4

Who is affected by CVE-2025-6705?

Any service account associated with Open VSX extensions that have not been properly secured can be affected by CVE-2025-6705.

5

How can an attacker leverage CVE-2025-6705?

An attacker can leverage CVE-2025-6705 by gaining access to an existing extension and running malicious scripts that compromise the service account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203