CVE-2026-1699

Source
https://cve.org/CVERecord?id=CVE-2026-1699
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1699.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1699
Published
2026-01-30T09:57:14Z
Modified
2026-10-08T02:50:56Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). An attacker could exfiltrate secrets, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and push malicious code to the repository.

Database specific
{
    "cna_assigner": "eclipse",
    "cwe_ids": [
        "CWE-829"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1699.json"
}
References

Affected packages

Git / github.com/eclipse-theia/theia-website

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-theia/theia-website
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1699.json"