CVE-2026-46580 Details
Description
In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions.
A vulnerability in Eclipse Theia versions prior to 1.71.0 allows for indirect prompt injection in AI chat features. Files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded, potentially overriding or extending the AI agent's system prompts. An attacker could create a malicious repository with prompt template files that replaced the AI's instructions with attacker-controlled content when the workspace was opened in Theia. This vulnerability, combined with other AI chat features available in untrusted workspaces, could lead to data exfiltration through Markdown image rendering or arbitrary command execution via task definitions.
Users can update to Eclipse Theia version 1.71.0 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/114 | [email protected] | Vendor AdvisoryPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| eclipse theia | < 1.71.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | Initial Analysis | [email protected] |
| Jun 19, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |