Vulnerability Description
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Theia | < 1.74.0 |
Related Weaknesses (CWE)
References
- https://github.com/eclipse-theia/theia/security/advisories/GHSA-qqc8-9538-25v4Broken Link
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/176Vendor Advisory
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/570Issue TrackingVendor Advisory
FAQ
What is CVE-2026-61891?
CVE-2026-61891 is a vulnerability with a CVSS score of 7.5 (HIGH). In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied UR...
How severe is CVE-2026-61891?
CVE-2026-61891 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-61891?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Theia.