CVE-2026-46580CWE-1427CWE-829

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or…

High · published June 18, 2026

CVSS v4.0
8.4
EPSS
1%
Percentile
41.4
In the wild
Unconfirmed
What it is

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions.

The record
Technical detail
CVSS v4.0
8.4 · HIGH
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00507 · 41.4th percentile
Weaknesses
CWE-1427 · Improper Neutralization of Input Used for LLM Prompting; CWE-829 · Inclusion of Functionality from Untrusted Control Sphere
Published
2026-06-18T14:26Z
EPSS history
Timeline
  • 18 JUN 14:26Z
    In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or…
    cvelistv5