Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82217

Quick assessment

Affected
Eclipse Foundation Eclipse Theia
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Eclipse Theia 版本 1.73.0 至 1.75.0(不含)中,AI“Agent 模式”下的文件变更工具( 、 以及替换和状态辅助函数)在解析由模型提供的文件路径时,未进行工作区包含性检查(workspace-containment check)。因此,精心构造的相对路径(如 )、绝对路径或经 展开的路径,都可以利用 Theia 后端操作系统的用户权限,在工作区之外写入或删除文件。 由于路径参数受模型输出影响,攻击者可以通过间接提示注入(indirect prompt injection)来引导该路

CVSS 8.8 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
Eclipse Foundation Eclipse Theia 1.73.0< 1.75.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82217

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path such as ../.bashrc, an absolute path, or a ~-expanded path could therefore write or delete files outside the workspace with the privileges of the Theia backend OS user. Because the path argument is influenced by model output, it can be steered through indirect prompt injection, and in Agent Mode writes are applied without a confirmation dialog. Writing to a host-executed file such as a shell startup file or ~/.ssh/authorized_keys can escalate to code execution on the backend.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Eclipse Foundation Eclipse Theia 1.73.0 ~ 1.75.0 -

II. Public POCs for CVE-2026-82217

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82217

登录查看更多情报信息。

Vendor Advisories for CVE-2026-82217 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-82217

No comments yet


Leave a comment