CVE-2026-10054 | Eclipse Theia up to 1.72.x Browser Backend /services/shell-terminal missing origin validation in websockets (GHSA-78g8-vm3p-97c6)
A vulnerability described as critical has been identified in Eclipse Theia up to 1.72.x. This issue affects some unknown processing of the file /services/shell-terminal of the component Browser Backend. Such manipulation leads to missing origin validation in websockets.
This vulnerability is traded as CVE-2026-10054. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More