PT-2026-50691 · Eclipse Foundation · Eclipse Theia
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse Theia versions prior to 1.71.0
Description
Files matching the pattern
.prompts/*.prompttemplate in a workspace are automatically loaded, allowing them to override or extend the AI agent's system prompts. This enables indirect prompt injection, where an attacker crafts a malicious repository with prompt template files that replace the AI's system instructions with attacker-controlled content when the workspace is opened. When combined with other AI chat features in untrusted workspaces, this can lead to attack chains resulting in arbitrary command execution via task definitions or data exfiltration through Markdown image rendering.Recommendations
Update to version 1.71.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Theia