MEDIUM
Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or Content-Disposition: attachment
Published Jun 23, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.31%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.