Description
In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.
Remediation
References
https://github.com/eclipse-theia/theia/issues/7954
https://omespino.com/write-up-google-bug-bounty-xss-to-cloud-shell-instance-takeover-rce-as-root-5000-usd/
Related Vulnerabilities
CVE-2023-26156 Vulnerability in maven package org.webjars.npm:chromedriver
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-jdbc
CVE-2018-16330 Vulnerability in npm package editor.md
CVE-2023-34602 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.12