In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat.
Update @theia/debug to 1.69.0; @theia/task to 1.69.0; @theia/workspace to 1.69.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scan[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions affects @theia/debug (npm), @theia/task (npm), @theia/workspace (npm). Severity is high. In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat.
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| @theia/debugnpm |
In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat.
Update @theia/debug to 1.69.0; @theia/task to 1.69.0; @theia/workspace to 1.69.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scan[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions affects @theia/debug (npm), @theia/task (npm), @theia/workspace (npm). Severity is high. In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat.
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| @theia/debugnpm |
| <1.69.0 |
| 1.69.0 |
| @theia/tasknpm | <1.69.0 | 1.69.0 |
|---|
| @theia/workspacenpm | <1.69.0 | 1.69.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| <1.69.0 |
| 1.69.0 |
| @theia/tasknpm | <1.69.0 | 1.69.0 |
|---|
| @theia/workspacenpm | <1.69.0 | 1.69.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard