CVE-2026-61891: Path Traversal
In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend exposes HTTP file-download endpoints (GET /file, GET /files/, PUT /files/) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example /etc/hosts, SSH keys, or tokens). Electron mode uses a separate ElectronSecurityToken and is not affected via this path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61891?
CVE-2026-61891 has a severity rating of 7.5, indicating a high risk level.
How do I fix CVE-2026-61891?
To fix CVE-2026-61891, upgrade Eclipse Theia to version 1.74.0 or later, which addresses this vulnerability.
What type of vulnerability is CVE-2026-61891?
CVE-2026-61891 is classified as a Path Traversal vulnerability, which can lead to information leakage.
What versions of Eclipse Theia are affected by CVE-2026-61891?
CVE-2026-61891 affects all versions of Eclipse Theia up to and including 1.73.1.
What are the potential impacts of CVE-2026-61891?
Exploitation of CVE-2026-61891 can allow attackers to access files beyond the intended workspace, leading to information disclosure.