What is CVE-2026-12609?
A path traversal vulnerability exists in the `@theia/plugin-ext` backend of Eclipse Theia versions 1.66.0 through 1.73.1. The `/hostedPlugin/:pluginId/:path(*)` endpoint fails to properly validate file paths, enabling an unauthenticated remote attacker to read arbitrary files outside the plugin directory. Immediate upgrade or restricting access to this endpoint is strongly recommended.
Azərbaycanca: Eclipse Theia-nın 1.66.0-dən 1.73.1-ə qədər versiyalarında `@theia/plugin-ext` backend-də path traversal zəifliyi aşkar edilib. `/hostedPlugin/:pluginId/:path(*)` endpoint-i fayl yolunu düzgün yoxlamır, bu da uzaqdan autentifikasiya olunmamış hücumçuya plug-in qovluğundan kənarda ixtiyari faylları oxumağa imkan verir. Dərhal ən son versiyaya yenilənməli və ya endpoint-ə giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Eclipse Theia
FAQ2
Which versions of Eclipse Theia are affected by CVE-2026-12609?
This path traversal vulnerability affects Eclipse Theia versions 1.66.0 through 1.73.1.
What can an attacker do by exploiting CVE-2026-12609?
An unauthenticated remote attacker can read arbitrary files outside the plugin directory by exploiting improper file path validation in the `/hostedPlugin/:pluginId/:path(*)` endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.