CVE Explorer
CVE-2025-6705
A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing a privileged token. This token enabled the publishing of new extension versions under any namespace, including those not controlled by an attacker. However, it did not permit deletion of existing extensions, overwriting of published versions, or access to administ
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-913","description":"CWE-913 Improper Control of Dynamically-Managed Code Resources","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8779018e7233b47dcc49209bf187b1917ed8e52812f1dae8231a38d957e2fc04 · sha256:185a0b73d75ad939… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-653","description":"CWE-653 Improper Isolation or Compartmentalization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8779018e7233b47dcc49209bf187b1917ed8e52812f1dae8231a38d957e2fc04 · sha256:185a0b73d75ad939… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"collectionURL":"https://open-vsx.org","defaultStatus":"unaffected","product":"Eclipse Open VSX Registry","vendor":"Eclipse Foundation","versions":[{"status":"affected","version":"date < 20250624","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8779018e7233b47dcc49209bf187b1917ed8e52812f1dae8231a38d957e2fc04 · sha256:185a0b73d75ad939… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.6,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"H…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8779018e7233b47dcc49209bf187b1917ed8e52812f1dae8231a38d957e2fc04 · sha256:185a0b73d75ad939… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-913","description":"CWE-913 Improper Control of Dynamically-Managed Code Resources","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8779018e7233b47dcc49209bf187b1917ed8e52812f1dae8231a38d957e2fc04 · sha256:185a0b73d75ad939… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-653","description":"CWE-653 Improper Isolation or Compartmentalization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8779018e7233b47dcc49209bf187b1917ed8e52812f1dae8231a38d957e2fc04 · sha256:185a0b73d75ad939… · /containers/cna/problemTypes/1/descriptions/0
Source references
2 source assertions{"tags":["patch"],"url":"https://github.com/EclipseFdn/publish-extensions/pull/881"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8779018e7233b47dcc49209bf187b1917ed8e52812f1dae8231a38d957e2fc04 · sha256:185a0b73d75ad939… · /containers/cna/references/1
{"tags":["product"],"url":"https://open-vsx.org"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8779018e7233b47dcc49209bf187b1917ed8e52812f1dae8231a38d957e2fc04 · sha256:185a0b73d75ad939… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.