Open VSX Bug Lets Malicious Extensions Slip Through
A fail-open flaw in Open VSX allowed attackers to bypass extension scanning, letting malicious VS Code-compatible plugins go live until the fix on 11 February 2026.
Source: Koi Security
Read more: CyberSecBrief

















