CVE-2026-14574 | Eclipse Theia up to 1.73.1 Preference Utils PreferenceUtils.merge prototype pollution
A vulnerability classified as critical was found in Eclipse Theia up to 1.73.1. The impacted element is the function PreferenceUtils.merge of the component Preference Utils. Such manipulation leads to improperly controlled modification of object prototype attributes.
This vulnerability is uniquely identified as CVE-2026-14574. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More