High severityNVD Advisory· Published Jun 18, 2026· Updated Jun 19, 2026
CVE-2026-44691
CVE-2026-44691
Description
In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@theia/debugnpm | < 1.69.0 | 1.69.0 |
@theia/tasknpm | < 1.69.0 | 1.69.0 |
@theia/workspacenpm | < 1.69.0 | 1.69.0 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-g9jw-92q7-g7fjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-44691ghsaADVISORY
- github.com/eclipse-theia/theia/issues/16889ghsaWEB
- github.com/eclipse-theia/theia/pull/16917ghsaWEB
- gitlab.eclipse.org/security/cve-assignment/-/work_items/116ghsaWEB
- gitlab.eclipse.org/security/vulnerability-reports/-/work_items/331ghsaWEB
News mentions
0No linked articles in our index yet.