Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-61891 |
|
Path Traversal in eclipse (CVE-2026-61891)
path traversal in eclipse (CVE-2026-61891). Confidential information can be exposed externally. Exploitable via `GET /file`.
|
| CVE-2026-60009 |
|
Path Traversal in eclipse (CVE-2026-60009)
path traversal in eclipse (CVE-2026-60009). Successful exploitation can lead to full system takeover. Exploitable via `POST /file-upload`.
|
| CVE-2026-12609 |
|
Path Traversal in eclipse (CVE-2026-12609)
path traversal in eclipse (CVE-2026-12609). Confidential information can be exposed externally.
|
| CVE-2026-14574 |
|
Vulnerability in eclipse (CVE-2026-14574)
vulnerability in eclipse (CVE-2026-14574). Data can be tampered with by attackers. Exploitable via ``PreferenceUtils.merge``.
|
| CVE-2026-44691 |
|
Vulnerability in @theia/debug (CVE-2026-44691)
vulnerability in @theia/debug (CVE-2026-44691). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.69.0` or later.
|
| CVE-2026-46580 |
|
Vulnerability in @theia/ai-chat-ui (CVE-2026-46580)
vulnerability in @theia/ai-chat-ui (CVE-2026-46580). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.71.0` or later.
|
| CVE-2026-44688 |
|
Vulnerability in @theia/ai-chat-ui (CVE-2026-44688)
vulnerability in @theia/ai-chat-ui (CVE-2026-44688). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.71.0` or later.
|
| CVE-2026-22551 |
|
Vulnerability in @theia/ai-chat-ui (CVE-2026-22551)
vulnerability in @theia/ai-chat-ui (CVE-2026-22551). Confidential information can be exposed externally. Mitigation: upgrade to `1.71.0` or later.
|