PT-2026-5388 · Eclipse · Eclipse Theia - Website

Barak Haryati

·

Publicado

2026-01-30

·

Atualizado

2026-01-30

·

CVE-2026-1699

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Theia Website (affected versions not specified)
Description The GitHub Actions workflow located at .github/workflows/preview.yml in the Eclipse Theia Website repository utilized the pull request target trigger, which allowed for the execution of untrusted pull request code. This enabled any GitHub user to execute arbitrary code within the repository's CI environment, gaining access to repository secrets and a GITHUB TOKEN possessing extensive write permissions, including permissions for contents, packages, pages, and actions. An attacker could potentially exfiltrate sensitive information, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and introduce malicious code into the repository.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1699

Produtos afetados

Eclipse Theia - Website