Indirect Prompt Injection in Eclipse Theia Affects AI Functionality
CVE-2026-46580
8.4HIGH
What is CVE-2026-46580?
In Eclipse Theia versions before 1.71.0, a vulnerability allows maliciously crafted prompt template files in a workspace to compromise AI agent instructions. This indirect prompt injection can lead to an attacker replacing the AI's system prompts with harmful content. When a user opens a workspace containing these files, the AI's behavior may be manipulated, opening the door to data exfiltration through Markdown image rendering or execution of arbitrary commands through specifically designed task definitions. This poses a significant risk, especially in untrusted environments.
Affected Version(s)
Eclipse Theia 0 < 1.71.0
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Piotr Ryciak (https://gitlab.eclipse.org/void01)
