{"data":{"id":"379c5eae-9d1a-49fb-a85e-6bebf2d5a4c7","title":"CVE-2026-82217: In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI \"Agent Mode\" file-change tools (writeFileContent","summary":"Eclipse Theia versions 1.73.0 to 1.75.0 have a vulnerability in AI 'Agent Mode' where file-writing tools don't check if file paths stay within the workspace (the allowed project folder). An attacker can use prompt injection (tricking the AI by hiding instructions in its input) to make the AI write files anywhere on the system, potentially modifying shell startup files or SSH keys to run malicious code with the privileges of the server running Theia.","solution":"Update to Eclipse Theia version 1.75.0 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82217","publishedAt":"2026-08-31T14:17:26.610Z","cveId":"CVE-2026-82217","cweIds":["CWE-22"],"cvssScore":"8.8","cvssSeverity":"high","severity":"high","attackType":["prompt_injection","supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Eclipse Theia"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-31T14:17:26.610Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010","AML.T0051"]}}