PT-2026-50689 · Eclipse Foundation · Eclipse Theia
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse Theia versions prior to 1.71.0
Description
The AI chat agent processes workspace file and directory names as part of its prompt context without distinguishing them from system instructions. This allows for indirect prompt injection, where an attacker crafts a malicious repository with adversarial names that force the AI agent to follow attacker-controlled instructions. When used in untrusted workspaces, this can lead to attack chains resulting in arbitrary command execution via task definitions or data exfiltration through Markdown image rendering.
Recommendations
Update to version 1.71.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Theia