CVE-2026-19884: Eclipse theia vulnerability
In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own @theia/git extension and the builtin VS Code git extension run git commands such as git status as soon as a repository is detected. Since git honors repository-local configuration, a folder containing an attacker-controlled .git/config with core.fsmonitor (or a comparable hook-like setting) causes the configured command to be executed. The configuration can be delivered by burying a bare repository inside a regular repository (OVE-20210718-0001), so cloning an attacker-supplied repository and opening it in a Theia-based application is sufficient to execute arbitrary commands with the privileges of the user, without any confirmation prompt.
As of 1.70.0, plugins that declare capabilities.untrustedWorkspaces.supported: false, which includes the builtin git extension, are no longer loaded or activated in an untrusted workspace, and the deprecated @theia/git extension has been removed, so no git command is executed against an untrusted folder.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eclipse Theiato a version that resolves this vulnerability.Fixed in 1.70.0 - Remove
Remove
@theia/gitfrom your environment.Remove the deprecated @theia/git extension (not loaded/activated in untrusted workspaces starting with Theia 1.70.0; git commands against untrusted folders are prevented).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19884?
The severity of CVE-2026-19884 is rated at 80, indicating a high level of risk.
What does CVE-2026-19884 mean for Eclipse Theia users?
CVE-2026-19884 means that users can unintentionally start source control integration without trusting the folder first, potentially exposing sensitive information.
How do I fix CVE-2026-19884?
To fix CVE-2026-19884, users should upgrade to Eclipse Theia version 1.69.1 or later, where the issue has been addressed.
Which versions of Eclipse Theia are affected by CVE-2026-19884?
CVE-2026-19884 affects all versions of Eclipse Theia up to and including 1.69.0.
Does CVE-2026-19884 affect custom applications built on Theia?
Yes, CVE-2026-19884 affects any custom applications built on Theia that include the git integration.