CVE-2026-60009 | Eclipse Theia up to 1.73.x move uri unrestricted upload

SecurityVulns

A vulnerability identified as critical has been detected in Eclipse Theia up to 1.73.x. This affects the function move. Performing a manipulation of the argument uri results in unrestricted upload.

This vulnerability is reported as CVE-2026-60009. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More