Executive brief
Eclipse Theia, a platform for building cloud and desktop IDEs, is vulnerable to a security flaw where malicious code can be executed automatically when a user opens a compromised project. An attacker could create a deceptive repository that, once opened, runs unauthorized commands with the user's full permissions. This could lead to complete system compromise, data theft, or the installation of malware on the developer's machine.
Technical details
Eclipse Theia versions prior to 1.69.0 fail to enforce workspace trust requirements for custom task definitions located in workspace configuration files such as .theia/tasks.json or .vscode/tasks.json. This vulnerability (CWE-829) allows an attacker to achieve arbitrary command execution with the privileges of the local user by enticing them to open a malicious repository. The risk is further amplified when combined with AI chat features; if a workspace's .theia/settings.json disables tool confirmation, the malicious tasks can be triggered automatically via an AI chat message. The issue is resolved in version 1.69.0.
Affected products
- Eclipse Foundation Eclipse Theia < 1.69.0
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory