Executive brief
Eclipse Theia, a platform for building cloud and desktop IDEs, contains a vulnerability in its AI chat integration. An attacker can create a malicious project repository that, when opened by a user, automatically overrides the AI's internal instructions. This can be used to trick the AI into stealing sensitive data or executing unauthorized commands on the user's computer.
Technical details
Eclipse Theia versions prior to 1.71.0 are vulnerable to indirect prompt injection. The application automatically loads workspace files matching the `.prompts/*.prompttemplate` pattern and uses them to define or extend the AI agent's system prompts without sufficient isolation. By crafting a malicious repository, an attacker can gain control over the AI's instructions when a user opens the workspace. This can be chained with other features to achieve data exfiltration via Markdown image rendering or arbitrary command execution through task definitions. The issue is addressed in version 1.71.0.
Affected products
- Eclipse Foundation Theia < 1.71.0
Timeline
- 2026-06-18: advisory: Initial disclosure by Eclipse Foundation
- 2026-06-18: patched: Fix released in version 1.71.0