---
cve: "CVE-2026-61891"
severity: "HIGH"
cvss: 7.5
epss: "45%"
vendor: "Eclipse Foundation"
kev: false
exploited: false
published: "2026-08-05 12:18:57"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T12:23:14+02:00"
---

# CVE-2026-61891

> 7.5 HIGH · 🧪 PoC

## Beschreibung

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- 172494ea2564ca07690e230805861146007fae79 (Commit)

## Referenzen

- <https://github.com/eclipse-theia/theia/security/advisories/GHSA-qqc8-9538-25v4>
- <https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/570>
- <https://gitlab.eclipse.org/security/cve-assignment/-/work_items/176>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-61891) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
