Description
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
Remediation
References
https://bugs.eclipse.org/bugs/show_bug.cgi?id=575924
https://github.com/eclipse-theia/theia/pull/10125
Related Vulnerabilities
CVE-2022-38900 Vulnerability in npm package decode-uri-component
CVE-2021-21353 Vulnerability in npm package pug-code-gen
CVE-2020-26938 Vulnerability in npm package oauth2-server
CVE-2022-22984 Vulnerability in npm package snyk-sbt-plugin
CVE-2023-30530 Vulnerability in maven package org.jenkins-ci.plugins:consul-kv-builder