Back to overview

CVE-2026-1699

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). An attacker could exfiltrate secrets, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and push malicious code to the repository.

Metadata

CVE ID
CVE-2026-1699
State
PUBLISHED
Assigner
eclipse
Reserved
2026-01-30 09:38 UTC
Published
2026-01-30 09:57 UTC
Last updated
2026-02-02 19:26 UTC
Primary CWE
CWE-829
CWE-829 Inclusion of Functionality from Untrusted Control Sp…
Vendor / Product
Eclipse Foundation / Eclipse Theia - Website
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Eclipse Foundation Eclipse Theia - Website 0 < 2fb0cc4bfc372cfaef79feb4eebb6563778b2560
Weakness (CWE)
CWESourceDescription
CWE-829 cna CWE-829 Inclusion of Functionality from Untrusted Control Sphere
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview