What is CVE-2026-14574?
In Eclipse Theia versions 0.7.0 through 1.73.1, the `PreferenceUtils.merge` function fails to reject prototype-related keys like `__proto__`, leading to a prototype pollution vulnerability in `@theia/core`. This could allow remote code execution or privilege escalation; users should update to the latest patched version immediately.
Azərbaycanca: Eclipse Theia-nın 0.7.0-dan 1.73.1-ə qədər versiyalarında `PreferenceUtils.merge` funksiyası `__proto__`, `constructor` kimi prototip açarlarını süzgəcdən keçirmədiyi üçün prototype pollution zəifliyi mövcuddur. Bu, uzaqdan kod icrasına (RCE) və ya imtiyaz yüksəldilməsinə səbəb ola bilər; istifadəçilər dərhal yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Eclipse Theia are affected by the CVE-2026-14574 prototype pollution vulnerability?
This vulnerability affects Eclipse Theia versions 0.7.0 through 1.73.1.
What are the potential impacts of exploiting the CVE-2026-14574 vulnerability?
Exploiting this vulnerability could allow remote code execution (RCE) or privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.