What is CVE-2026-60009?
CVE-2026-60009 is a file upload vulnerability in Eclipse Theia versions up to 1.73.1 via the `@theia/filesystem` backend. The `POST /file-upload` endpoint fails to validate the absolute path from the `uri` field, allowing a remote attacker to move or overwrite arbitrary files on the server. Immediate mitigation involves upgrading Theia or disabling the affected endpoint.
Azərbaycanca: CVE-2026-60009 Eclipse Theia-nın 1.73.1-ə qədər versiyalarında `@theia/filesystem` backend üzərindən fayl yükləmə zəifliyidir. `POST /file-upload` sorğusunda `uri` parametri ilə təqdim edilən mütləq yol yoxlanılmır, bu da uzaqdan hücumçunun ixtiyari faylı serverdə başqa yerə daşımasına və ya üzərinə yazmasına imkan verir. Dərhal Theia-nı ən son versiyaya yeniləmək və ya təsirlənmiş endpoint-i deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which endpoint is exploited in Eclipse Theia for CVE-2026-60009?
The vulnerability is exploited via the `POST /file-upload` endpoint in the `@theia/filesystem` backend.
What is the immediate recommended mitigation for CVE-2026-60009?
Upgrade Theia to the latest version beyond 1.73.1 or disable the affected endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.