Sploitus

CVE-2026-19884

No indexed exploits for CVE-2026-19884 yet

In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own `@theia/git` extension and the builtin VS Code `git` extension run git commands such as `git status` as soon as a repository is detected. Since git honors repository-local configuration, a folder containing an attacker-controlled `.git/config` with `core.fsmonitor` (or a comparable hook-like setting) causes the configured command to be executed. The configuration can be delivered by burying a bare repository inside a regular repository (OVE-20210718-0001), so cloning an attacker-supplied repository and opening it in a Theia-based application is sufficient to execute arbitrary commands with the privileges of the user, without any confirmation prompt. As of 1.70.0, plugins that declare `capabilities.untrustedWorkspaces.supported: false`, which includes the builtin git extension, are no longer loaded or activated in an untrusted workspace, and the deprecated `@theia/git` extension has been removed, so no git command is executed against an untrusted folder.

Affected products
Eclipse Theia, Vscode
Fix
Available
CVSS 4.0
8.4 HIGH
EPSS
0.1% (3th percentile)
Weakness
CWE-15, CWE-829
NVD status
Awaiting Analysis
Published
2026-08-14
Attack patterns
CAPEC-176, CAPEC-549
CVE-2026-19884 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-19884 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-19884 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.