Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Eclipse Theia AI chat prompt injection and data exfiltration flaws before 1.71.0

Three vulnerabilities in Eclipse Theia versions prior to 1.71.0 allowed a malicious workspace to inject instructions into the AI chat agent via file/directory names or auto-loaded .prompts/*.prompttemplate files, and to exfiltrate workspace or conversation data through unrestricted Markdown image requests or run arbitrary commands via task definitions. Workspace trust enforcement added in v1.71.0 disables AI features in untrusted workspaces and mitigates the documented attack chain.

Disclosed 18 June 2026 · Record updated 13 September 2026

Impact

Indirect prompt injection from a malicious repository could lead to exfiltration of sensitive workspace or conversation data to attacker-controlled servers and arbitrary command execution via task definitions.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-22551
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44688
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-46580