Description
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
Remediation
References
https://github.com/eclipse-theia/theia/issues/7283
Related Vulnerabilities
CVE-2021-4307 Vulnerability in maven package org.webjars.bower:baobab
CVE-2023-36469 Vulnerability in maven package org.xwiki.platform:xwiki-platform-notifications-ui
CVE-2018-11696 Vulnerability in npm package node-sass
CVE-2020-9489 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2020-26302 Vulnerability in maven package org.webjars.bowergithub.arasatasaygin:is.js