CVE-2026-60009
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement and no authentication. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests.
Read full descriptionShow less
Because `multipart/form-data` is a CORS-safelisted request type, a cross-origin web page can trigger the write with no preflight and no credentials, resulting in an unauthenticated arbitrary file write outside the workspace to any absolute path the backend process can write. This can escalate to remote code execution, for example by overwriting a startup-executed file such as `~/.bashrc`. Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Base score: 8.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.44%
- Percentile among all scored CVEs: 36
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1189Drive-by Compromiseinitial access85 % - Primary impact
T1565.001Stored Data Manipulationimpact90 % - Secondary impact
T1059Command and Scripting Interpreterexecution80 % - Secondary impact
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access70 %
XSS-like CORS bypass sin autenticación en POST /file-upload permite escritura arbitraria de archivos (CWE-22). La interacción es del navegador comprometido (UI:R). Escalable a RCE reescribiendo bashrc (T1059), con acceso a credenciales via sobreescritura de archivos de configuración (T1078.001).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-22, CWE-73, CWE-306, CWE-352
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-60009",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-60009",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-05T12:36:40.861334Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "emo@eclipse.org",
"affectedData": [
{
"vendor": "Eclipse Foundation",
"product": "Eclipse Theia",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.74.0",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-05T11:16:25.363",
"references": [
{
"url": "https://github.com/eclipse-theia/theia/security/advisories/GHSA-62f6-wcvg-54h3",
"tags": [
"Broken Link"
],
"source": "emo@eclipse.org"
},
{
"url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/177",
"tags": [
"Vendor Advisory"
],
"source": "emo@eclipse.org"
},
{
"url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/595",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "emo@eclipse.org"
},
{
"url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/595",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"description": [
{
"lang": "en",
"value": "CWE-22"
},
{
"lang": "en",
"value": "CWE-73"
},
{
"lang": "en",
"value": "CWE-306"
},
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement and no authentication. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests. Because `multipart/form-data` is a CORS-safelisted request type, a cross-origin web page can trigger the write with no preflight and no credentials, resulting in an unauthenticated arbitrary file write outside the workspace to any absolute path the backend process can write. This can escalate to remote code execution, for example by overwriting a startup-executed file such as `~/.bashrc`. Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path."
}
],
"lastModified": "2026-08-07T15:54:02.380",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "670EAAD9-2B91-4846-B5B2-09E075AACF1F",
"versionEndExcluding": "1.74.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "emo@eclipse.org"
}