Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-22551

In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-controlled servers. The workspace trust enforcement introduced in v1.71.0 mitigates the documented attack chain by disabling AI features in untrusted workspaces.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 7.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-22551
  • Eclipse » Theia » Version: N/A
    cpe:2.3:a:eclipse:theia:-
  • Eclipse » Theia » Version: 0.0.1
    cpe:2.3:a:eclipse:theia:0.0.1
  • Eclipse » Theia » Version: 0.1.0
    cpe:2.3:a:eclipse:theia:0.1.0
  • Eclipse » Theia » Version: 0.1.1
    cpe:2.3:a:eclipse:theia:0.1.1
  • Eclipse » Theia » Version: 0.10.0
    cpe:2.3:a:eclipse:theia:0.10.0
  • Eclipse » Theia » Version: 0.11.0
    cpe:2.3:a:eclipse:theia:0.11.0
  • Eclipse » Theia » Version: 0.12.0
    cpe:2.3:a:eclipse:theia:0.12.0
  • Eclipse » Theia » Version: 0.13.0
    cpe:2.3:a:eclipse:theia:0.13.0
  • Eclipse » Theia » Version: 0.14.0
    cpe:2.3:a:eclipse:theia:0.14.0
  • Eclipse » Theia » Version: 0.15.0
    cpe:2.3:a:eclipse:theia:0.15.0
  • Eclipse » Theia » Version: 0.16.0
    cpe:2.3:a:eclipse:theia:0.16.0
  • Eclipse » Theia » Version: 0.16.1
    cpe:2.3:a:eclipse:theia:0.16.1
  • Eclipse » Theia » Version: 0.2.0
    cpe:2.3:a:eclipse:theia:0.2.0
  • Eclipse » Theia » Version: 0.2.1
    cpe:2.3:a:eclipse:theia:0.2.1
  • Eclipse » Theia » Version: 0.2.2
    cpe:2.3:a:eclipse:theia:0.2.2
  • Eclipse » Theia » Version: 0.2.3
    cpe:2.3:a:eclipse:theia:0.2.3
  • Eclipse » Theia » Version: 0.2.4
    cpe:2.3:a:eclipse:theia:0.2.4
  • Eclipse » Theia » Version: 0.3.0
    cpe:2.3:a:eclipse:theia:0.3.0
  • Eclipse » Theia » Version: 0.3.1
    cpe:2.3:a:eclipse:theia:0.3.1
  • Eclipse » Theia » Version: 0.3.10
    cpe:2.3:a:eclipse:theia:0.3.10
  • Eclipse » Theia » Version: 0.3.11
    cpe:2.3:a:eclipse:theia:0.3.11
  • Eclipse » Theia » Version: 0.3.12
    cpe:2.3:a:eclipse:theia:0.3.12
  • Eclipse » Theia » Version: 0.3.13
    cpe:2.3:a:eclipse:theia:0.3.13
  • Eclipse » Theia » Version: 0.3.14
    cpe:2.3:a:eclipse:theia:0.3.14
  • Eclipse » Theia » Version: 0.3.15
    cpe:2.3:a:eclipse:theia:0.3.15
  • Eclipse » Theia » Version: 0.3.16
    cpe:2.3:a:eclipse:theia:0.3.16
  • Eclipse » Theia » Version: 0.3.17
    cpe:2.3:a:eclipse:theia:0.3.17
  • Eclipse » Theia » Version: 0.3.18
    cpe:2.3:a:eclipse:theia:0.3.18
  • Eclipse » Theia » Version: 0.3.19
    cpe:2.3:a:eclipse:theia:0.3.19
  • Eclipse » Theia » Version: 0.3.2
    cpe:2.3:a:eclipse:theia:0.3.2
  • Eclipse » Theia » Version: 0.3.3
    cpe:2.3:a:eclipse:theia:0.3.3
  • Eclipse » Theia » Version: 0.3.4
    cpe:2.3:a:eclipse:theia:0.3.4
  • Eclipse » Theia » Version: 0.3.6
    cpe:2.3:a:eclipse:theia:0.3.6
  • Eclipse » Theia » Version: 0.3.7
    cpe:2.3:a:eclipse:theia:0.3.7
  • Eclipse » Theia » Version: 0.3.8
    cpe:2.3:a:eclipse:theia:0.3.8
  • Eclipse » Theia » Version: 0.3.9
    cpe:2.3:a:eclipse:theia:0.3.9
  • Eclipse » Theia » Version: 0.4.0
    cpe:2.3:a:eclipse:theia:0.4.0
  • Eclipse » Theia » Version: 0.5.0
    cpe:2.3:a:eclipse:theia:0.5.0
  • Eclipse » Theia » Version: 0.6.0
    cpe:2.3:a:eclipse:theia:0.6.0
  • Eclipse » Theia » Version: 0.6.1
    cpe:2.3:a:eclipse:theia:0.6.1
  • Eclipse » Theia » Version: 0.7.0
    cpe:2.3:a:eclipse:theia:0.7.0
  • Eclipse » Theia » Version: 0.7.1
    cpe:2.3:a:eclipse:theia:0.7.1
  • Eclipse » Theia » Version: 0.7.2
    cpe:2.3:a:eclipse:theia:0.7.2
  • Eclipse » Theia » Version: 0.8.0
    cpe:2.3:a:eclipse:theia:0.8.0
  • Eclipse » Theia » Version: 0.9.0
    cpe:2.3:a:eclipse:theia:0.9.0
  • Eclipse » Theia » Version: 1.1.0
    cpe:2.3:a:eclipse:theia:1.1.0
  • Eclipse » Theia » Version: 1.10.0
    cpe:2.3:a:eclipse:theia:1.10.0
  • Eclipse » Theia » Version: 1.11.0
    cpe:2.3:a:eclipse:theia:1.11.0
  • Eclipse » Theia » Version: 1.12.0
    cpe:2.3:a:eclipse:theia:1.12.0
  • Eclipse » Theia » Version: 1.12.1
    cpe:2.3:a:eclipse:theia:1.12.1
  • Eclipse » Theia » Version: 1.14.0
    cpe:2.3:a:eclipse:theia:1.14.0
  • Eclipse » Theia » Version: 1.15.0
    cpe:2.3:a:eclipse:theia:1.15.0
  • Eclipse » Theia » Version: 1.16.0
    cpe:2.3:a:eclipse:theia:1.16.0
  • Eclipse » Theia » Version: 1.17.0
    cpe:2.3:a:eclipse:theia:1.17.0
  • Eclipse » Theia » Version: 1.17.1
    cpe:2.3:a:eclipse:theia:1.17.1
  • Eclipse » Theia » Version: 1.17.2
    cpe:2.3:a:eclipse:theia:1.17.2
  • Eclipse » Theia » Version: 1.18.0
    cpe:2.3:a:eclipse:theia:1.18.0
  • Eclipse » Theia » Version: 1.19.0
    cpe:2.3:a:eclipse:theia:1.19.0
  • Eclipse » Theia » Version: 1.2.0
    cpe:2.3:a:eclipse:theia:1.2.0
  • Eclipse » Theia » Version: 1.3.0
    cpe:2.3:a:eclipse:theia:1.3.0
  • Eclipse » Theia » Version: 1.4.0
    cpe:2.3:a:eclipse:theia:1.4.0
  • Eclipse » Theia » Version: 1.5.0
    cpe:2.3:a:eclipse:theia:1.5.0
  • Eclipse » Theia » Version: 1.6.0
    cpe:2.3:a:eclipse:theia:1.6.0
  • Eclipse » Theia » Version: 1.7.0
    cpe:2.3:a:eclipse:theia:1.7.0
  • Eclipse » Theia » Version: 1.8.0
    cpe:2.3:a:eclipse:theia:1.8.0
  • Eclipse » Theia » Version: 1.8.1
    cpe:2.3:a:eclipse:theia:1.8.1
  • Eclipse » Theia » Version: 1.9.0
    cpe:2.3:a:eclipse:theia:1.9.0


Contact Us

Shodan ® - All rights reserved