CVE-2026-35454Disclosure(coder / code-marketplace)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch coder code-marketplace systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulnerability in coder/code-marketplace allowed a malicious VSIX file to write arbitrary files outside the extension directory. ExtractZip passed raw zip entry names to a callback that wrote files via filepath.Join with no boundary check; filepath.Join resolved .. components but did not prevent the result from escaping the base path. This vulnerability is fixed in 2.4.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • code-marketplace

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
code-marketplace

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-05: 1Mentions · 2026-04-06: 1Mentions · 2026-04-07: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-05: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 104-0504-0604-07
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-051
Disclosure1
2026-04-061
Patch1
2026-04-071
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-35454 The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulnerability in coder/code-marketplace allowed a ma… https://www.cve.org/CVERecord?id=CVE-2026-35454

    Post summary

    CVE-2026-35454 is a Zip Slip vulnerability affecting the Code Extension Marketplace before version 2.4.2, which has been addressed by that release; no PoC, exploit, or active usage is reported.

    00010188
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35454 Zip Slip Vulnerability in Code Extension Marketplace Before 2.4.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35454

    Post summary

    CVE-2026-35454 is a Zip Slip vulnerability affecting the Code Extension Marketplace before version 2.4.2, potentially allowing arbitrary file write.

    0000044
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A path traversal flaw (CVE-2026-35454) affects `Code Extension Marketplace` platforms. Malicious extensions could write files to arbitrary locations during installation. Monitor vendor advisories for mitigations. #infosec #pathtraversal https://www.pulsepatch.io/posts/cve-2026-35454-code-extension-marketplace-zip-slip

    Post summary

    CVE-2026-35454 is a path‑traversal flaw in Code Extension Marketplace platforms that lets malicious extensions write arbitrary files during installation; advisories are pending.

    0000049
    4 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcodercode-marketplace---

Explore more