Eclipse Foundation · Eclipse Theia · CVE-2026-22551
**Name of the Vulnerable Software and Affected Versions**
Eclipse Theia versions prior to 1.71.0
**Description**
The AI chat renders Markdown image tags from AI responses, which triggers unrestricted HTTP requests to arbitrary external URLs. When combined with prompt injection in a malicious workspace, an attacker can force the AI agent to create image URLs that encode sensitive information from the conversation context or workspace, allowing the data to be exfiltrated to servers controlled by the attacker.
**Recommendations**
Update to version 1.71.0 or later to enable workspace trust enforcement, which disables AI features in untrusted workspaces.