Loading
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo.
Use CWE-283, Eclipse vendor hub and Open Vsx product page to widen CVE-2025-1007 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-6705 for nearby disclosures in the same product family.