Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @theia/ai-code-completion
  4. ›
  5. CVE-2026-44688

CVE-2026-44688: [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat

June 18, 2026 (updated June 19, 2026)

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by the AI agent, would cause the agent to follow attacker-controlled instructions (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions.

References

  • github.com/advisories/GHSA-3jww-hxqj-wfq2
  • github.com/eclipse-theia/theia/commit/e3fdfe6992389bc5fa611058d00c39d7408508ed
  • github.com/eclipse-theia/theia/issues/16892
  • github.com/eclipse-theia/theia/pull/17364
  • gitlab.eclipse.org/security/cve-assignment/-/work_items/113
  • nvd.nist.gov/vuln/detail/CVE-2026-44688

Code Behaviors & Features

Detect and mitigate CVE-2026-44688 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.71.0

Fixed versions

  • 1.71.0

Solution

Upgrade to version 1.71.0 or above.

Impact 7.8 HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-829: Inclusion of Functionality from Untrusted Control Sphere

Source file

npm/@theia/ai-code-completion/CVE-2026-44688.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 20 Jun 2026 12:17:04 +0000.