Code Execution Vulnerability in Eclipse Theia by GitHub Actions
CVE-2026-1699

10CRITICAL

Key Information:

Vendor
CVE Published:
30 January 2026

What is CVE-2026-1699?

A vulnerability in the Eclipse Theia Website repository leverages the GitHub Actions workflow in a manner that permits untrusted code execution. The use of the pull_request_target trigger allows any GitHub user to execute potentially malicious code within the Continuous Integration (CI) environment, providing unauthorized access to repository secrets and the GITHUB_TOKEN. This access enables attackers to exfiltrate sensitive information, publish harmful packages, and manipulate the official Theia website, potentially compromising the integrity of the project.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Eclipse Theia - Website 0 < 2fb0cc4bfc372cfaef79feb4eebb6563778b2560

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Barak Haryati | JFrog
.