๐Ÿ” CVE Alert

CVE-2026-19884

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own `@theia/git` extension and the builtin VS Code `git` extension run git commands such as `git status` as soon as a repository is detected. Since git honors repository-local configuration, a folder containing an attacker-controlled `.git/config` with `core.fsmonitor` (or a comparable hook-like setting) causes the configured command to be executed. The configuration can be delivered by burying a bare repository inside a regular repository (OVE-20210718-0001), so cloning an attacker-supplied repository and opening it in a Theia-based application is sufficient to execute arbitrary commands with the privileges of the user, without any confirmation prompt. As of 1.70.0, plugins that declare `capabilities.untrustedWorkspaces.supported: false`, which includes the builtin git extension, are no longer loaded or activated in an untrusted workspace, and the deprecated `@theia/git` extension has been removed, so no git command is executed against an untrusted folder.

CWE CWE-829 CWE-15
Vendor eclipse foundation
Product eclipse theia
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse theia

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse theia are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Theia
0 < 1.70.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-theia/theia/pull/16809 github.com: https://github.com/eclipse-theia/theia/pull/17098 github.com: https://github.com/eclipse-theia/theia/pull/17148 gitlab.eclipse.org: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/175 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/231

Credits

Sudhanshu (https://gitlab.eclipse.org/sudi)