Eclipse

Theia

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 14.08.2026 15:32:38
  • Zuletzt bearbeitet 18.08.2026 15:04:46

In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Thei...

  • EPSS 0.46%
  • Veröffentlicht 05.08.2026 11:03:01
  • Zuletzt bearbeitet 07.08.2026 15:48:50

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the fil...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 05.08.2026 10:59:24
  • Zuletzt bearbeitet 07.08.2026 15:54:02

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs....

  • EPSS 0.41%
  • Veröffentlicht 05.08.2026 10:55:42
  • Zuletzt bearbeitet 07.08.2026 20:23:46

In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without veri...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 05.08.2026 10:51:47
  • Zuletzt bearbeitet 07.08.2026 16:02:40

In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this...

  • EPSS 0.3%
  • Veröffentlicht 03.07.2026 10:30:57
  • Zuletzt bearbeitet 06.07.2026 18:56:27

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full re...

  • EPSS 0.16%
  • Veröffentlicht 03.07.2026 10:11:32
  • Zuletzt bearbeitet 07.07.2026 05:16:48

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin validation in @...

  • EPSS 0.41%
  • Veröffentlicht 18.06.2026 14:35:25
  • Zuletzt bearbeitet 22.06.2026 19:47:14

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned a...

  • EPSS 0.31%
  • Veröffentlicht 18.06.2026 14:32:01
  • Zuletzt bearbeitet 22.06.2026 20:03:38

In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could...

  • EPSS 0.51%
  • Veröffentlicht 18.06.2026 14:26:59
  • Zuletzt bearbeitet 22.06.2026 19:45:40

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository contai...