← Back

CVE-2026-1699

nvd nist
Published: Jan 30, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). An attacker could exfiltrate secrets, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and push malicious code to the repository.

Affected (1)

1 product
Theia Website
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2026-01-22

References (1)

Source: emo@eclipse.org
ExploitIssue TrackingVendor Advisory

Timeline

No history available yet.