GHSA-w6v7-w58j-pg5r
GitHub Security Advisory
Improper Verification of Communication Channel in @theia/plugin-ext
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
Affected Packages
npm
@theia/plugin-ext
Affected versions:
0
(fixed in 1.18.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 26, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.