Executive brief
Eclipse Theia is a cloud and desktop IDE framework that includes AI-powered chat and code completion features. An attacker can craft a malicious repository with specially crafted file and directory names that trick the AI chat agent into executing unintended instructions. This could lead to sensitive data exposure or arbitrary command execution when developers open untrusted projects.
Technical details
The vulnerability is an indirect prompt injection (CWE-1427, CWE-829) in Eclipse Theia's AI chat feature. The root cause is that workspace file and directory names are included in the AI agent's prompt context without distinction from legitimate system instructions. An attacker who controls repository content can create adversarial directory or file names that, when processed by the AI agent, cause it to follow injected instructions. The attack requires opening an untrusted workspace and interacting with AI features; no authentication is required. Successful exploitation can lead to arbitrary command execution through task definition manipulation or sensitive data exfiltration via externally rendered Markdown images in AI chat output. The fix (version 1.71.0+) integrates workspace trust controls into AI features, preventing template loading and variable resolution in untrusted workspaces and gating AI execution on workspace trust status.
Affected products
- Eclipse Theia < 1.71.0
- Eclipse @theia/ai-chat-ui < 1.71.0
- Eclipse @theia/ai-chat < 1.71.0
- Eclipse @theia/ai-claude-code < 1.71.0
- Eclipse @theia/ai-code-completion < 1.71.0
- Eclipse @theia/ai-core < 1.71.0
- Eclipse @theia/ai-editor < 1.71.0
- Eclipse @theia/ai-ide < 1.71.0
Timeline
- 2026-06-18: disclosed: Advisory published
- 2026-04-28: patched: Fix merged in version 1.71.0 (PR #17364)