File Path Vulnerability in Eclipse Theia by Eclipse
CVE-2026-82217

8.8HIGH

Key Information:

Vendor
CVE Published:
31 August 2026

What is CVE-2026-82217?

Eclipse Theia versions 1.73.0 up to but not including 1.75.0 are vulnerable to a file path manipulation issue in the AI 'Agent Mode' feature. Specifically, it allows an attacker to resolve model-supplied file paths without proper containment checks, enabling the potential to write or delete files outside the designated workspace. This vulnerability can be exploited through crafted relative paths, absolute paths, or home-directory expanded paths, permitting unauthorized file modifications or deletions with the privileges of the backend OS user. Risk escalates as these actions are executed without user confirmation, creating opportunities for attackers to manipulate sensitive files, including shell startup files or authorized SSH keys, which could lead to further compromise of the backend system.

Affected Version(s)

Eclipse Theia 1.73.0 < 1.75.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khoa Bui
.