Directory Traversal Vulnerability in Eclipse Theia Plugin Extension
CVE-2026-12609
7.5HIGH
What is CVE-2026-12609?
In affected versions of Eclipse Theia, the backend of the @theia/plugin-ext exposes an insecure HTTP endpoint that does not adequately validate file paths. This oversight allows network attackers to manipulate file paths with encoded sequences to escape the intended directory, leading to unauthorized access to sensitive files on the server. The exploit can be initiated without authentication, making it particularly dangerous for installations that do not sufficiently restrict access to the plugin functionalities.
Affected Version(s)
Eclipse Theia 1.66.0 < 1.74.0
