Releases181
Frequency2 weeks 4 days
Last Release
Stars21.6K
Eclipse Theia is a cloud & desktop IDE framework implemented in TypeScript.

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM4.3 MEDIUM

In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().

6.1 MEDIUM4.3 MEDIUM

In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.

6.1 MEDIUM4.3 MEDIUM

In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.

9.6 CRITICAL9.3 HIGH

In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.