Vulnerabilities/

Improper Neutralization of Input in Theia console

Severity:
Medium

Description

In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.

Recommendation

Update the @theia/console package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@theia/console
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing