CVE-2026-61891 PUBLISHED

Assigner: eclipse
Reserved: 15.07.2026 Published: 05.08.2026 Updated: 05.08.2026

In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend exposes HTTP file-download endpoints (GET /file, GET /files/, PUT /files/) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in @theia/core re-issues the cookie and calls next() without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example /etc/hosts, SSH keys, or tokens). Electron mode uses a separate ElectronSecurityToken and is not affected via this path.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor Eclipse Foundation
Product Eclipse Theia
Versions Default: unaffected
  • affected from 0 to 1.74.0 (excl.)

Credits

  • Christian Damus (http://github.com/cdamus, https://gitlab.eclipse.org/cdamus) finder

References

Problem Types

  • CWE-22 CWE
  • CWE-36 CWE
  • CWE-200 CWE
  • CWE-306 CWE

Impacts

  • CAPEC-126
  • CAPEC-597