QID 981062

QID 981062: Nodejs (npm) Security Update for @theia/mini-browser (GHSA-v9w2-v7j9-rjpr)

In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to GHSA-v9w2-v7j9-rjpr for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981062

    Software Advisories
    Advisory ID Software Component Link
    GHSA-v9w2-v7j9-rjpr @theia/mini-browser URL Logo github.com/advisories/GHSA-v9w2-v7j9-rjpr