CVE-2026-19884: Eclipse theia vulnerability

Published Aug 14, 2026
·
Updated

In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own @theia/git extension and the builtin VS Code git extension run git commands such as git status as soon as a repository is detected. Since git honors repository-local configuration, a folder containing an attacker-controlled .git/config with core.fsmonitor (or a comparable hook-like setting) causes the configured command to be executed. The configuration can be delivered by burying a bare repository inside a regular repository (OVE-20210718-0001), so cloning an attacker-supplied repository and opening it in a Theia-based application is sufficient to execute arbitrary commands with the privileges of the user, without any confirmation prompt.

As of 1.70.0, plugins that declare capabilities.untrustedWorkspaces.supported: false, which includes the builtin git extension, are no longer loaded or activated in an untrusted workspace, and the deprecated @theia/git extension has been removed, so no git command is executed against an untrusted folder.

Affected Software

1 affected component
Eclipse theia<=1.69.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Eclipse Theia to a version that resolves this vulnerability.

    Fixed in 1.70.0
  2. Remove

    Remove @theia/git from your environment.

    Remove the deprecated @theia/git extension (not loaded/activated in untrusted workspaces starting with Theia 1.70.0; git commands against untrusted folders are prevented).

Event History

Aug 14, 2026
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-19884?

The severity of CVE-2026-19884 is rated at 80, indicating a high level of risk.

2

What does CVE-2026-19884 mean for Eclipse Theia users?

CVE-2026-19884 means that users can unintentionally start source control integration without trusting the folder first, potentially exposing sensitive information.

3

How do I fix CVE-2026-19884?

To fix CVE-2026-19884, users should upgrade to Eclipse Theia version 1.69.1 or later, where the issue has been addressed.

4

Which versions of Eclipse Theia are affected by CVE-2026-19884?

CVE-2026-19884 affects all versions of Eclipse Theia up to and including 1.69.0.

5

Does CVE-2026-19884 affect custom applications built on Theia?

Yes, CVE-2026-19884 affects any custom applications built on Theia that include the git integration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203