Vulnerability  ·  2026-08-15

Eclipse Theia IDE — untrusted-folder Git integration bypasses trust prompt

VulnerabilityHigh impactGlobalCVE-2026-19884
NVD published CVE-2026-19884 (CVSS 8.4, High) on 2026-08-14, describing a workspace-trust bypass in Eclipse Theia's git integration that starts source control operations on folder open, before any trust decision is made by the user.
Theia underlies several AI-assisted coding IDEs; a workspace-trust bypass at folder-open time is directly relevant to the growing class of attacks where a malicious repository exploits an AI coding agent's trust model to achieve unintended code execution before the user has vetted the folder.
Opening a folder starts source control integration without requiring the user to trust the folder first, allowing repository-embedded configuration or hooks to execute git operations before the workspace-trust boundary is established
Eclipse Theia ≤ 1.69.0 (@theia/git extension and Theia IDE)
Upgrade Eclipse Theia beyond 1.69.0; disable git integration for untrusted folders until patched
Eclipse Theia PR #16809
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →