File Path Vulnerability in Eclipse Theia by Eclipse
CVE-2026-82217
What is CVE-2026-82217?
Eclipse Theia versions 1.73.0 up to but not including 1.75.0 are vulnerable to a file path manipulation issue in the AI 'Agent Mode' feature. Specifically, it allows an attacker to resolve model-supplied file paths without proper containment checks, enabling the potential to write or delete files outside the designated workspace. This vulnerability can be exploited through crafted relative paths, absolute paths, or home-directory expanded paths, permitting unauthorized file modifications or deletions with the privileges of the backend OS user. Risk escalates as these actions are executed without user confirmation, creating opportunities for attackers to manipulate sensitive files, including shell startup files or authorized SSH keys, which could lead to further compromise of the backend system.
Affected Version(s)
Eclipse Theia 1.73.0 < 1.75.0
