# CVE-2025-1007

## Summary

- **CVE ID:** CVE-2025-1007
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-285, CWE-283
- **Published:** Feb 19, 2025
- **Last Modified:** Mar 13, 2026

## Description

In OpenVSX version v0.9.0 to v0.20.0, the 
/user/namespace/{namespace}/details API allows a user to edit all 
namespace details, even if the user is not a namespace Owner or 
Contributor. The details include: name, description, website, support 
link and social media links. The same issues existed in 
/user/namespace/{namespace}/details/logo and allowed a user to change 
the logo.

## Affected Products

- Eclipse Foundation — OpenVSX (0.9.0)
- Eclipse Foundation — OpenVSX (0.19.1)

## References

- [CNA](https://github.com/eclipse/openvsx/security/advisories/GHSA-wc7c-xq2f-qp4h)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.50%
- **EPSS Percentile:** 41.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._