Vulnerabilities/

Command Injection in @theia/messages

Severity:
Medium

Description

In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.

Recommendation

Update the @theia/messages package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@theia/messages
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing