← Back to search

CVE-2026-61891

7.5 HIGHpublic exploit available

Published 2026-08-05 · Updated 2026-08-07

AI risk analysis

Summary
The flaw allows unauthenticated clients to read any file accessible by the backend process due to improper URI handling and lack of proper token validation in non-Electron deployments.
Exploitability
Exploitation is relatively easy as no valid token is required for HTTP requests, making it a significant security risk.
Blast radius
If exploited, this could lead to data breaches, unauthorized access to sensitive files, and potential system compromise.
Prioritized remediation
Update to the latest version of Eclipse Theia (1.74 or later) which addresses this vulnerability.
auth-bypassfile-readwebeclipse

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-22, CWE-36, CWE-200, CWE-306

Vendors

eclipse

Products

theia

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.