Directory Traversal Vulnerability in Eclipse Theia Plugin Extension
CVE-2026-12609

7.5HIGH

Key Information:

Vendor
CVE Published:
5 August 2026

What is CVE-2026-12609?

In affected versions of Eclipse Theia, the backend of the @theia/plugin-ext exposes an insecure HTTP endpoint that does not adequately validate file paths. This oversight allows network attackers to manipulate file paths with encoded sequences to escape the intended directory, leading to unauthorized access to sensitive files on the server. The exploit can be initiated without authentication, making it particularly dangerous for installations that do not sufficiently restrict access to the plugin functionalities.

Affected Version(s)

Eclipse Theia 1.66.0 < 1.74.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

http://github.com/geo-chen
.