PatchSiren

eclipse-theia CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH eclipse-theia CVE published 2026-08-05

CVE-2026-12609

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T11:16:24.080Z and has not been modified since then. The Eclipse Theia versions 1.66.0 to 1.73.1 are affected by a high-severity path traversal vulnerability in the `@theia/plugin-ext` backend. An unauthenticated network attacker can send percent-encoded `../` sequences to escape the plugin direct [truncated]