In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions.
References
| Link | Resource |
|---|---|
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/114 | Vendor Advisory Patch |
Configurations
History
22 Jun 2026, 19:45
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:* | |
| References | () https://gitlab.eclipse.org/security/cve-assignment/-/work_items/114 - Vendor Advisory, Patch | |
| First Time |
Eclipse theia
Eclipse |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
19 Jun 2026, 06:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-18 16:16
Updated : 2026-06-22 19:45
NVD link : CVE-2026-46580
Mitre link : CVE-2026-46580
CVE.ORG link : CVE-2026-46580
JSON object : View
Products Affected
eclipse
- theia
CWE
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
