AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-60009

HIGH · CVSS 8.8 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Eclipse Theia versions up to 1.73.1 are vulnerable due to an insecure file upload mechanism in the `@theia/filesystem` backend, allowing attackers to exploit the `POST /file-upload` endpoint to perform unauthenticated arbitrary file writes to any absolute path on the server. This vulnerability can lead to significant impacts, including remote code execution if critical files are overwritten. Organizations using affected versions of Eclipse Theia should prioritize patching this vulnerability to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-60009
Severity
HIGH
CVSS
8.8
EPSS
0.32%

Original NVD Description

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement and no authentication. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests. Because `multipart/form-data` is a CORS-safelisted request type, a cross-origin web page can trigger the write with no preflight and no credentials, resulting in an unauthenticated arbitrary file write outside the workspace to any absolute path the backend process can write. This can escalate to remote code execution, for example by overwriting a startup-executed file such as `~/.bashrc`. Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.

Related CVEs

Other vulnerabilities affecting the same vendor(s)