Home

Description

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat.

PUBLISHED Reserved 2026-05-22 | Published 2026-06-18 | Updated 2026-06-18 | Assigner eclipse




HIGH: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-829: Inclusion of Functionality from Untrusted Control Sphere

Product status

Default status
unaffected

Any version before 1.69.0
affected

Credits

Piotr Ryciak (https://gitlab.eclipse.org/void01) finder

References

gitlab.eclipse.org/security/cve-assignment/-/work_items/116

cve.org (CVE-2026-44691)

nvd.nist.gov (CVE-2026-44691)

Download JSON