CVE-2021-28161

MEDIUM

Eclipse Theia <= 1.8.0 - Stored Cross-Site Scripting in Debug Console

Title source: llm
STIX 2.1

Description

In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/eclipse-theia/theia/issues/8794

Scores

CVSS v3 6.1
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
eclipse/theia < 1.8.0
theia/console 0 - 1.8.1npm
Published Mar 12, 2021
Tracked Since Feb 18, 2026