Impact
UrlUtil.getBaseUrl in Eclipse Open VSX constructs absolute URLs for assets and download links from the X‑Forwarded‑Host, X‑Forwarded‑Proto and X‑Forwarded‑Prefix headers without validating the source of these headers. A malicious client can send a single crafted HTTP request with forged header values, causing the service to generate URLs that point to attacker‑controlled locations. Because the generated metadata is cached under keys that do not include the host, every other client that retrieves the cached entry will be instructed to download a malicious VSIX package, its signature and public key, all provided by the attacker. This enables an unauthenticated attacker to deliver arbitrary code to downstream Visual Studio Code‑compatible editors, achieving remote code execution.
Affected Systems
The affected product is Eclipse Open VSX, distributed by the Eclipse Foundation. Any deployed instance of the service that accepts client‑supplied X‑Forwarded‑Host, X‑Forwarded‑Proto or X‑Forwarded‑Prefix headers without filtering these headers is vulnerable. The advisory does not specify exact version numbers, but the flaw exists in all versions prior to the forthcoming patch.
Risk and Exploitability
With a CVSS score of 9.1 the flaw is considered high‑severity. The EPSS score shows a very low probability of exploitation in the wild (<1%), likely because the vulnerability requires direct or proxy‑forwarded access to the Open VSX service. The vulnerability is not yet listed in the CISA KEV catalog. An unauthenticated attacker who can reach the service directly, or through a proxy that does not overwrite the forwarded headers, can exploit this flaw by sending a crafted request, resulting in cache poisoning and remote code execution on any client that later fetches the poisoned metadata.
OpenCVE Enrichment