CVE-2026-22551Medium▾ Sunlit[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.2%
0.2% → 0.3%
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-controlled servers. The workspace trust enforcement introduced in v1.71.0 mitigates the documented attack chain by disabling AI features in untrusted workspaces.
@theia/ai-chat-ui < 1.71.0@theia/ai-chat < 1.71.0@theia/ai-claude-code < 1.71.0@theia/ai-code-completion < 1.71.0@theia/ai-core < 1.71.0@theia/ai-editor < 1.71.0@theia/ai-ide < 1.71.0Upgrade to a patched release:
@theia/ai-chat-ui 1.71.0@theia/ai-chat 1.71.0@theia/ai-claude-code 1.71.0@theia/ai-code-completion 1.71.0@theia/ai-core 1.71.0@theia/ai-editor 1.71.0@theia/ai-ide 1.71.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44688High[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
CVE-2026-46580High[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat
CVE-2026-44691High[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
GHSA-vx52-2968-3vc6High· 7.4pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
CVE-2026-55553High· 7.5urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features
CVE-2026-54660High· 7.4swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`