CVE-2026-46580High▾ Twilight[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
0.3% → 0.5%
In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions.
@theia/ai-chat-ui < 1.71.0@theia/ai-chat < 1.71.0@theia/ai-claude-code < 1.71.0@theia/ai-code-completion < 1.71.0@theia/ai-core < 1.71.0@theia/ai-editor < 1.71.0Upgrade to a patched release:
@theia/ai-chat-ui 1.71.0@theia/ai-chat 1.71.0@theia/ai-claude-code 1.71.0@theia/ai-code-completion 1.71.0@theia/ai-core 1.71.0@theia/ai-editor 1.71.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44688High[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
CVE-2026-22551Medium[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
CVE-2026-44691High[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
CVE-2025-70974Critical· 10.0Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class
CVE-2026-59176High· 7.8functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
CVE-2026-62680High· 7.1Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications