CVE-2026-1699Disclosure(eclipse / theia_website)

LOWCVSS 8.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). An attacker could exfiltrate secrets, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and push malicious code to the repository.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • theia_website

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
theia_website

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-01-30: 5Technical Details · 2026-01-30: 401-30
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1699 In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing unt… https://www.cve.org/CVERecord?id=CVE-2026-1699

    Post summary

    A newly identified CVE-2026-1699 in the Eclipse Theia Website repository’s GitHub Actions workflow (using pull_request_target) highlights a potential code execution vulnerability, without any PoC, exploit code, or patch information.

    00010239
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1699: CRITICAL] Vulnerability in Theia Website repo allowed executing arbitrary code in CI environment with access to secrets and GITHUB_TOKEN, leading to potential data exfiltration and malicious ac...#cve,CVE-2026-1699,#cybersecurity https://cvefind.com/CVE-2026-1699

    Post summary

    The post announces CVE‑2026‑1699, a critical vulnerability in Theia’s website repo that enables arbitrary code execution in CI environments, potentially exposing secrets.

    00000110
    584 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1699 GitHub Actions Workflow Vulnerability in Eclipse Theia Website Repository https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1699

    Post summary

    The content briefly notes CVE-2026-1699 as a GitHub Actions Workflow vulnerability in the Eclipse Theia website repository and provides a link to a vulnerability details page, but offers no further information.

    0000078
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1699 - Critical In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request ... https://www.thehackerwire.com/vulnerability/CVE-2026-1699/ https://t.co/9PiWpcPDwi

    Post summary

    CVE‑2026‑1699 is a critical flaw in the Eclipse Theia website’s GitHub Actions workflow that allows execution of untrusted pull requests, but no PoC, exploit code, active attacks, or patch information is provided.

    0000067
    113 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1699: Eclipse Foundation (CVSS: 10.0)... Classic pull_request_target misuse in Eclipse Theia gives attackers full CI access - trivial to exfiltrate secrets and p... https://zerodaysignal.com/vulnerability/CVE-2026-1699 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑1699, noting a CVSS 10.0 score and a misuse of pull_request_target in Eclipse Theia that gives attackers full CI access and easy secret exfiltration.

    0000071
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeclipsetheia_website---

Explore more