OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-90882

HIGH · CVSS 8.7 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability allows any origin to make credentialed requests to the authenticated /user endpoints of the open-vsx.org deployment, potentially exposing sensitive user information such as login names, tokens, and namespaces. This could lead to the exfiltration of personal access tokens, enabling attackers to perform unauthorized actions on behalf of the victim. Organizations using this service should prioritize addressing this issue, particularly those managing user credentials and sensitive data.

CVE
CVE-2026-90882
Severity
HIGH
CVSS
8.7
EPSS
0.44%

Original NVD Description

The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to the service in a logged-in user's browser and read the responses. This exposed /user (login name, avatar, homepage, tokens URL), /user/tokens, /user/namespaces, /user/extensions, /user/search/{name} and /user/namespace/{name}/members, and — because /user/csrf was readable the same way — allowed the CSRF protection on write endpoints to be defeated. Chaining the two, an attacker page could call /user/token/create and exfiltrate a personal access token carrying publish and delete rights over the victim's namespaces. The headers were emitted by the CDN/edge layer, not by the application: the Open VSX software sets allowCredentials(true) in exactly one place, against a single exact origin derived from ovsx.webui.url, and defines no CORS mapping on /user/ beyond it. No configuration of the software produces origin reflection with credentials.