AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-1699

CRITICAL · CVSS 10 EPSS 0.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-01-30 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 10.0. It affects GitHub.

CVE
CVE-2026-1699
Severity
CRITICAL
CVSS
10
EPSS
0.50%
GitHub

Original NVD Description

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). An attacker could exfiltrate secrets, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and push malicious code to the repository.

Related CVEs

Other vulnerabilities affecting the same vendor(s)