Vulnerability record · CVE-2021-34435 · published 1 September 2021
CVE-2021-34435: Eclipse theia origin validation error vulnerability
Eclipse · Theia
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..
Description
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=568018 | ExploitPatchVendor Advisory |
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=568018 | ExploitPatchVendor Advisory |
Track CVE-2021-34435 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-34435), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.