CVE-2026-1699
Last modified
CVE-2026-1699 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). An attacker could exfiltrate secrets, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and push malicious code to the repository.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Theia Website | < 2026-01-22 |
References
- https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/332Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-1699?
How severe is CVE-2026-1699?
How do I fix CVE-2026-1699?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16974The Kirki – Freeform Page Builder, Website Builder & Customi…6.4
- CVE-2026-16977The Form Maker by 10Web WordPress plugin before 1.15.45 doe…
- CVE-2026-1698A HTTP Host header attack vulnerability affects WebClient an…6.1
- CVE-2026-16981The DHL Shipping Germany for WooCommerce WordPress plugin be…5.3
- CVE-2026-16985The Squeeze WordPress plugin before 1.7.12 does not validat…8.8
- CVE-2026-16988The GeoDirectory WordPress plugin before 2.8.169 does not p…7.5
- CVE-2026-16990The Payment Button for PayPal WordPress plugin through 1.2.3…5.3
- CVE-2026-16992The Create WordPress plugin before 2.5.4 does not perform an…6.5
- CVE-2026-16993The DHL Shipping Germany for WooCommerce WordPress plugin be…3.7
- CVE-2026-16999Improper restriction of XML external entity reference vulner…6.3
- CVE-2026-1700A weakness has been identified in projectworlds House Rental…5.4
- CVE-2026-17002Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2026-1699?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
