In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path such as ../.bashrc, an absolute path, or a ~-expanded path could therefore write or delete files outside the workspace with the privileges of the Theia backend OS user. Because the path argument is influenced by model output, it can be steered through indirect prompt injection, and in Agent Mode writes are applied without a confirmation dialog. Writing to a host-executed file such as a shell startup file or ~/.ssh/authorized_keys can escalate to code execution on the backend.
History

Mon, 31 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Directory Traversal Allows Unauthorized File Write in Eclipse Theia's Agent Mode

Mon, 31 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse eclipse Theia
Vendors & Products Eclipse
Eclipse eclipse Theia

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) resolved a model-supplied file path without a workspace-containment check. A crafted relative path such as ../.bashrc, an absolute path, or a ~-expanded path could therefore write or delete files outside the workspace with the privileges of the Theia backend OS user. Because the path argument is influenced by model output, it can be steered through indirect prompt injection, and in Agent Mode writes are applied without a confirmation dialog. Writing to a host-executed file such as a shell startup file or ~/.ssh/authorized_keys can escalate to code execution on the backend.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published: 2026-08-31T13:40:56.645Z

Updated: 2026-09-01T03:56:19.988Z

Reserved: 2026-08-28T08:47:00.677Z

Link: CVE-2026-82217

cve-icon Vulnrichment

Updated: 2026-08-31T13:57:45.531Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T14:17:26.610

Modified: 2026-09-01T21:11:35.983

Link: CVE-2026-82217

cve-icon Redhat

No data.