AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-4983

MEDIUM · CVSS 4.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-23 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.1. See the original NVD description below for full technical details.

CVE
CVE-2026-4983
Severity
MEDIUM
CVSS
4.1
EPSS
0.22%

Original NVD Description

Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or Content-Disposition: attachment. This allows an attacker to publish an extension with a malicious SVG icon and achieve stored cross-site scripting (XSS) when a user navigates directly to the icon URL. On deployments using local storage, script execution occurs within the Open VSX application origin, enabling session hijacking, authentication token theft, and unauthorized extension publishing. On deployments backed by external storage (such as open-vsx.org with an S3-backed CDN), execution is confined to the storage origin, reducing impact but still permitting phishing attacks and credential harvesting through attacker-crafted pages.

Related CVEs

Other vulnerabilities affecting the same vendor(s)