Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
CVE-2026-14574
CVE-2026-14574
Description
In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges preference values without rejecting prototype-related keys (__proto__, constructor, prototype). Because this function is invoked by PreferenceServiceImpl.doResolve for every preference resolution across scopes (default, user, workspace, folder), a crafted preference value in a workspace settings file (.theia/settings.json or .vscode/settings.json) can pollute Object.prototype when the user opens the workspace, potentially altering application logic across the Theia process.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.