CVE-2026-10054Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin validation in @theia/core is fail-open: connections are accepted when the Origin header is missing or when no THEIA_HOSTS allowlist is configured (the default). The Socket.IO integration additionally replaces the real Origin header with a client-supplied fix-origin header that an attacker can control or omit. As a result, a foreign-origin web page visited by a user with a running Theia instance can open the /services WebSocket namespace, invoke terminal creation, attach to the resulting terminal data channel, execute arbitrary OS commands, and read their output. This affects both local developer setups (drive-by attack) and hosted or tunneled deployments without strong external authentication. A fix is in development that enforces same-origin validation by default, removes trust in the fix-origin header, gates HTTP and WebSocket access on a SameSite=Strict; HttpOnly connection-token cookie, and sanitizes shell terminal creation options.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-1385

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-03); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-03: 1Mentions · 2026-07-07: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-07: 107-0307-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH: CVE-2026-10054 | CVSS 8.8 Eclipse Theia (v1.8.1+) exposes privileged terminal RPC without auth. Remote attackers can execute arbitrary OS commands via WebSocket. Affects local dev & hosted deployments. Fix in development. #CVE #Vulnerability #PatchNow https://t.co/KRhoDff71D

    Post summary

    Eclipse Theia v1.8.1+ is vulnerable to remote code execution via an unauthenticated terminal RPC over WebSocket, with a fix currently under development.

    0000058
    66 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Eclipse Theia Unauthenticated Terminal RCE via WebSocket (CVE-2026-10054) Eclipse Theia's browser backend exposes a privileged terminal RPC over WebSocket (/services/shell-terminal) with no service-level authentication. Origin validation in @theia/core is fail-open — connections are accepted when the Origin header is missing or when no THEIA_HOSTS allowlist is set (the default). The http://Socket.IO layer makes it worse by trusting a client-controlled fix-origin header. The result: a malicious web page visited by a user running a Theia instance can open the WebSocket namespace, spawn a terminal, run arbitrary OS commands, and read the output. Hits both local dev setups (drive-by) and hosted/tunneled cloud deployments lacking strong external auth. 👉Affected: Eclipse Theia 1.8.1 through < 1.73.0

    Post summary

    The post announces a high-severity unauthenticated RCE in Eclipse Theia’s WebSocket implementation, detailing the vulnerability mechanism but providing no PoC, exploit, or patch information.

    00000111
    236 followersView on X

Explore more