Skip to content

Eclipse Theia vulnerabilities

3 CVEs tracked

Eclipse Theia appears in our latest reports with highly critical vulnerabilities. The primary threats involve unauthorized filesystem access via path traversal in the `@theia/plugin-ext` and `@theia/filesystem` backends, along with a prototype pollution flaw in the `@theia/core` library that could lead to code execution. Specifically, CVE-2026-12609, CVE-2026-61891, and CVE-2026-14574 affect versions up to and including 1.73.1. Defenders should immediately upgrade beyond version 1.73.1 and restrict network access to the exposed `filesystem` and `plugin-ext` endpoints.

Azərbaycanca: Eclipse Theia son hesabatlarımızda kritik dərəcədə ciddi zəifliklərlə diqqət çəkir. Əsas təhlükələr fayl sisteminə icazəsiz giriş (path traversal), serverdə ixtiyari fayl oxuma (`@theia/plugin-ext` və `@theia/filesystem` komponentlərində) və `@theia/core` kitabxanasında prototype pollution vasitəsilə kod ifrazı imkanlarıdır. Xüsusilə, CVE-2026-12609, CVE-2026-61891 və CVE-2026-14574 zəiflikləri 1.73.1 və daha əvvəlki versiyaları təsir edir. Müdafiəçilər dərhal 1.73.1-dən yuxarı versiyaya yeniləmə aparmalı, məruz qalan `filesystem` və `plugin-ext` endpoint-lərini şəbəkə səviyyəsində məhdudlaşdırmalıdır.

This vendor's CVEs3

This hub is built from skopnix's own reporting on Eclipse Theia: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.