Vulnerabilities/

[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions - @theia/debug

Severity:
High

Description

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user’s privileges.

Recommendation

Update the @theia/debug package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@theia/debug
Anything's wrong? Let us know Last updated on June 19, 2026