What is CVE-2026-19884?
CVE-2026-19884 affects Eclipse Theia up to version 1.69.0, where opening a folder automatically initiates source control integration without requiring user trust. This impacts applications using Git integration, like the Theia IDE, and could allow malicious operations from untrusted projects. Updating Theia is recommended to mitigate the risk.
Azərbaycanca: CVE-2026-19884 Eclipse Theia-nın 1.69.0 daxil olmaqla bütün versiyalarında aşkarlanıb: istifadəçi qovluğu etibar etmədən açdıqda Git kimi mənbə nəzarəti inteqrasiyası avtomatik başlayır. Bu, Theia IDE kimi tətbiqlərdə `@theia/git` genişlənməsindən istifadə edən sistemlərə təsir edir. Bu vəziyyət etibarsız layihələrin potensial zərərli əməliyyatlarına yol aça bilər, təcili olaraq Theia-nı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
Which versions of Eclipse Theia are affected by CVE-2026-19884?
CVE-2026-19884 affects all versions of Eclipse Theia up to and including 1.69.0.
What is the potential impact of exploiting CVE-2026-19884?
It could allow malicious operations from untrusted projects.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.