Eclipse / Theia
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-61891 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /f… | HIGH | 7.5 | Aug 5, 2026 |
| CVE-2026-60009 | In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The han… | HIGH | 8.8 | Aug 5, 2026 |
| CVE-2026-12609 | In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, w… | HIGH | 7.5 | Aug 5, 2026 |
| CVE-2026-14574 | In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values witho… | MEDIUM | 5.7 | Aug 5, 2026 |
| CVE-2026-44691 | In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without re… | HIGH | 8.4 | Jun 18, 2026 |
| CVE-2026-22551 | In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs with… | MEDIUM | 6.7 | Jun 18, 2026 |
| CVE-2026-46580 | In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or… | HIGH | 8.4 | Jun 18, 2026 |
| CVE-2026-44688 | In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing… | HIGH | 8.4 | Jun 18, 2026 |
| CVE-2021-41038 | In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage(). | MEDIUM | 6.1 | Nov 10, 2021 |
| CVE-2021-34436 | In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extens… | CRITICAL | 9.8 | Sep 2, 2021 |
| CVE-2021-34435 | In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it i… | HIGH | 8.8 | Sep 1, 2021 |
| CVE-2021-28162 | In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run. | MEDIUM | 6.1 | Mar 12, 2021 |
| CVE-2021-28161 | In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected. | MEDIUM | 6.1 | Mar 12, 2021 |
| CVE-2020-27224 | In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code. | CRITICAL | 9.6 | Feb 24, 2021 |
| CVE-2019-17636 | In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs… | HIGH | 8.1 | Mar 10, 2020 |
Showing 1 to 15 of 15 CVEs