VDB
Sign up
HIGH8.8

GHSA-v9w2-v7j9-rjpr

Remote code execution in Eclipse Theia

Quick fix

GHSA-v9w2-v7j9-rjpr — @theia/mini-browser: upgrade to the fixed version with the command below.

npm install @theia/mini-browser@1.9.0

Details

In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@theia/mini-browser
Introduced in: 0.3.9Fixed in: 1.9.0
Fixnpm install @theia/mini-browser@1.9.0

References