PT-2026-50690 · Eclipse Foundation · Eclipse Theia
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse Theia versions prior to 1.69.0
Description
Custom task definitions in workspace files, such as
.theia/tasks.json and .vscode/tasks.json, can be executed without requiring workspace trust. This allows an attacker to create a malicious repository that executes arbitrary commands with the user's privileges when cloned and opened. If AI chat features are used and the .theia/settings.json file is configured to disable tool confirmation, the execution can be triggered automatically via a message in the AI chat.Recommendations
Update to version 1.69.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Theia