CVE@CVEnewDisclosure
A newly identified CVE-2026-1699 in the Eclipse Theia Website repository’s GitHub Actions workflow (using pull_request_target) highlights a potential code execution vulnerability, without any PoC, exploit code, or patch information.
CVEFind.com@CveFindComDisclosure
The post announces CVE‑2026‑1699, a critical vulnerability in Theia’s website repo that enables arbitrary code execution in CI environments, potentially exposing secrets.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The content briefly notes CVE-2026-1699 as a GitHub Actions Workflow vulnerability in the Eclipse Theia website repository and provides a link to a vulnerability details page, but offers no further information.
The Hacker Wire@TheHackerWireDisclosure
CVE‑2026‑1699 is a critical flaw in the Eclipse Theia website’s GitHub Actions workflow that allows execution of untrusted pull requests, but no PoC, exploit code, active attacks, or patch information is provided.
0day Signal@0dayPublishingDisclosure
The post announces CVE‑2026‑1699, noting a CVSS 10.0 score and a misuse of pull_request_target in Eclipse Theia that gives attackers full CI access and easy secret exfiltration.