Description
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
Recommendation
Update the @theia/plugin-ext package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.18.0
- Patched version(s): 1.18.0
References
Related Issues
- Improper Neutralization of Input in Theia console - CVE-2021-28161
- Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell` - CVE-2025-31477
- Remote code execution in Eclipse Theia - CVE-2021-34435
- Script injection - @backstage/plugin-techdocs - CVE-2021-32661
You might also like:
- Tags:
- npm
- @theia/plugin-ext
Anything's wrong? Let us know Last updated on February 01, 2023


