Post #4507939
2026-08-14 16:02 UTC
Opening a booby-trapped code repository can run an attacker's commands in editors built on Eclipse Theia (the framework under Arduino IDE 2.x and other tools).
A crafted git config runs on folder open, no trust prompt. CVE-2026-19884, CVSS 8.4.
Fix: update to Theia 1.70.0.
https://suriq.io/blog/eclipse-theia-repo-open-command-execution-cve-2026-19884
#infosec #cybersecurity
Replies (0)
No replies.