What is CVE-2026-61891?
CVE-2026-61891 affects Eclipse Theia up to version 1.73.1, where the `@theia/filesystem` backend HTTP endpoints (`GET /file`, `GET /files/`, `PUT /files/`) do not restrict file access to the workspace. This allows unauthorized file access outside the intended directory, and users should update to a patched version.
Azərbaycanca: CVE-2026-61891, Eclipse Theia 1.73.1-ə qədər versiyalarda `@theia/filesystem` backend-də HTTP endpoint-lərdə (`GET /file`, `GET /files/`, `PUT /files/`) yol məhdudiyyətinin olmaması ilə bağlıdır. Bu, iş sahəsindən kənar fayllara icazəsiz girişə səbəb ola bilər. Bu boşluqdan qorunmaq üçün müvafiq versiyalara yeniləmə etmək lazımdır.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Eclipse Theia
FAQ2
Which versions of Eclipse Theia are vulnerable to CVE-2026-61891?
This vulnerability exists in Eclipse Theia up to version 1.73.1.
Which HTTP endpoints are affected by CVE-2026-61891?
The vulnerability affects the `GET /file`, `GET /files/`, and `PUT /files/` endpoints in the `@theia/filesystem` backend.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.