Critical severity9.8NVD Advisory· Published Sep 2, 2021· Updated Jun 17, 2026
CVE-2021-34436
CVE-2021-34436
Description
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 0.1.1 - 0.2.0
- Range: 0.1.1
Patches
Vulnerability mechanics
References
1- bugs.eclipse.org/bugs/show_bug.cginvdVendor Advisory
News mentions
0No linked articles in our index yet.