Vulnerabilidad · Publicado 05/08/2026
Eclipse Theia versiones hasta 1.73.1 contienen una vulnerabilidad que permite a atacantes descargar archivos arbitrarios del servidor sin restricción de directorio workspace. El backend `@theia/filesystem` no valida correctamente las rutas URI en endpoints HTTP, afectando especialmente despliegues en navegador donde la validación de tokens es insuficiente. Empresas LATAM usando Theia como IDE en la nube corren riesgo de exposición de fuentes, configuraciones sensibles y datos de negocio.
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.
Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-22, CWE-36, CWE-200, CWE-306
Publicado en NIST NVD.