[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions - @theia/debug
- Severity:
- High
Description
In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user’s privileges.
Recommendation
Update the @theia/debug package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.69.0
- Patched version(s): 1.69.0
References
Related Issues
- [Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions - @theia/task - CVE-2026-44691
- [Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions - CVE-2026-44691
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-chat-ui - CVE-2026-44688
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-chat - CVE-2026-44688
You might also like:
- Tags:
- npm
- @theia/debug
Anything's wrong? Let us know Last updated on June 19, 2026


