Web Hack List

Collected research

Don't open that XML: XXE to RCE in XML plugins for VS Code, Eclipse, Theia, ...

Shielder - Don’t open that XML: XXE to RCE in XML plugins for VS Code, Eclipse, Theia, …

The LSP4XML language server parses XML as soon as an editor opens or saves it, so a malicious file triggers an external entity fetch with no further user action. Its DTD cache then writes the downloaded file to a path taken from the entity URL without sanitising it, so a traversal drops an executable into an autostart folder and runs it at next login.

Record

Document
Shielder - Don’t open that XML: XXE to RCE in XML plugins for VS Code, Eclipse, Theia, …
Researcher
thezero and zi0black
Published by
Shielder
Date
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of thezero and zi0black, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .