@theia/ai-ide vulnerabilities
CVEs whose affected-version data names the @theia/ai-ide package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-22551Medium[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
▾ Sunlittheia · @theia/ai-chat-uiEPSS 0.31%via GHSA
CVE-2026-44688High[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
▾ Twilighttheia · @theia/ai-chat-uiEPSS 0.51%via GHSA