Vulnerabilities/

Cross-site Scripting (XSS) in Eclipse Theia

Severity:
High

Description

In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.

Recommendation

Update the @theia/preview package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@theia/preview
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing