In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-controlled servers. The workspace trust enforcement introduced in v1.71.0 mitigates the documented attack chain by disabling AI features in untrusted workspaces.
Update @theia/ai-chat to 1.71.0; @theia/ai-chat-ui to 1.71.0; @theia/ai-claude-code to 1.71.0; @theia/ai-code-completion to 1.71.0; @theia/ai-core to 1.71.0; @theia/ai-editor to 1.71.0; @theia/ai-ide to 1.71.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scan[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat affects @theia/ai-chat (npm), @theia/ai-chat-ui (npm), @theia/ai-claude-code (npm), @theia/ai-code-completion (npm), @theia/ai-core (npm), @theia/ai-editor (npm), @theia/ai-ide (npm). Severity is medium. In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-controlled servers. The workspace trust enforcement introduced in v1.71.0 mitigates the documented attack chain by disabling AI features in untrusted workspaces.
AI coding agents often install or upgrade packages automatically in npm. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-controlled servers. The workspace trust enforcement introduced in v1.71.0 mitigates the documented attack chain by disabling AI features in untrusted workspaces.
Update @theia/ai-chat to 1.71.0; @theia/ai-chat-ui to 1.71.0; @theia/ai-claude-code to 1.71.0; @theia/ai-code-completion to 1.71.0; @theia/ai-core to 1.71.0; @theia/ai-editor to 1.71.0; @theia/ai-ide to 1.71.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scan[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat affects @theia/ai-chat (npm), @theia/ai-chat-ui (npm), @theia/ai-claude-code (npm), @theia/ai-code-completion (npm), @theia/ai-core (npm), @theia/ai-editor (npm), @theia/ai-ide (npm). Severity is medium. In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-controlled servers. The workspace trust enforcement introduced in v1.71.0 mitigates the documented attack chain by disabling AI features in untrusted workspaces.
AI coding agents often install or upgrade packages automatically in npm. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
| Fixed version |
|---|
| @theia/ai-chatnpm | <1.71.0 | 1.71.0 |
|---|---|---|
| @theia/ai-chat-uinpm | <1.71.0 | 1.71.0 |
| @theia/ai-claude-codenpm | <1.71.0 | 1.71.0 |
| @theia/ai-code-completionnpm | <1.71.0 | 1.71.0 |
| @theia/ai-corenpm | <1.71.0 | 1.71.0 |
| @theia/ai-editornpm | <1.71.0 | 1.71.0 |
| @theia/ai-idenpm | <1.71.0 | 1.71.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Fixed version |
|---|
| @theia/ai-chatnpm | <1.71.0 | 1.71.0 |
|---|---|---|
| @theia/ai-chat-uinpm | <1.71.0 | 1.71.0 |
| @theia/ai-claude-codenpm | <1.71.0 | 1.71.0 |
| @theia/ai-code-completionnpm | <1.71.0 | 1.71.0 |
| @theia/ai-corenpm | <1.71.0 | 1.71.0 |
| @theia/ai-editornpm | <1.71.0 | 1.71.0 |
| @theia/ai-idenpm | <1.71.0 | 1.71.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard