CVE-2026-44688High▾ Twilight[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
0.3% → 0.5%
In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by the AI agent, would cause the agent to follow attacker-controlled instructions (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions.
@theia/ai-chat-ui < 1.71.0@theia/ai-chat < 1.71.0@theia/ai-claude-code < 1.71.0@theia/ai-code-completion < 1.71.0@theia/ai-core < 1.71.0@theia/ai-editor < 1.71.0@theia/ai-ide < 1.71.0Upgrade to a patched release:
@theia/ai-chat-ui 1.71.0@theia/ai-chat 1.71.0@theia/ai-claude-code 1.71.0@theia/ai-code-completion 1.71.0@theia/ai-core 1.71.0@theia/ai-editor 1.71.0@theia/ai-ide 1.71.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46580High[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat
CVE-2026-22551Medium[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
CVE-2026-44691High[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
CVE-2025-70974Critical· 10.0Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class
CVE-2026-59176High· 7.8functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
CVE-2026-62680High· 7.1Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications