[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-core
- Severity:
- High
Description
In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions.
Recommendation
Update the @theia/ai-core package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.71.0
- Patched version(s): 1.71.0
References
Related Issues
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - CVE-2026-44688
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-ide - CVE-2026-44688
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-code-completion - CVE-2026-44688
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-claude-code - CVE-2026-44688
You might also like:
- Tags:
- npm
- @theia/ai-core
Anything's wrong? Let us know Last updated on June 19, 2026


