Tox
1 totalFDE578D55F8B692C4EB2CB5518C8B4FEE05F1620085F30302D782A2778FBEA12302B1B3EEAF5
Eclipse is the vendor/organization referenced for the affected products Eclipse Theia and Eclipse ThreadX.
Profile source: Mallory opens in a new tabEclipse
Eclipse is the vendor/organization referenced for the affected products Eclipse Theia and Eclipse ThreadX. The content identifies Eclipse Theia as impacted by CVE-2026-46580, a high-severity prompt injection vulnerability affecting versions prior to 1.71.0, where workspace files matching .prompts/*.prompttemplate could be auto-loaded and used to override or extend AI agent system prompts. The described impact includes potential chaining to data exfiltration via Markdown image rendering and arbitrary command execution via task definitions, with remediation to upgrade to Theia 1.71.0 or later and restrict untrusted workspace features. The content also identifies Eclipse ThreadX as an embedded development suite for resource-constrained devices and notes multiple vulnerabilities in Eclipse ThreadX NetX Duo at git commit 6c8e9d1, including a denial-of-service flaw in the NetX HTTP server and integer underflow vulnerabilities in HTTP server PUT request handling, all triggerable via crafted network traffic. No high-confidence information about Eclipse’s size or location is directly provided in the content.
FDE578D55F8B692C4EB2CB5518C8B4FEE05F1620085F30302D782A2778FBEA12302B1B3EEAF5-----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEE/8PbziZ69FoT2txN7627qmhWPUIFAmp1QR8ACgkQ7627qmhW PUKorQv/Z89eWhEVT9kY3Dhkbq0LcZ8MuJqdGaU0Hn0VaOuyfqqo151HcEIBU1+Z k0UuDRND2yDFIc8UwZQUyz5ut3KlICcyH0XkeowjiBRhQCiYW6k04NUvr9yFNjPK QUEbWnYLrdtTTWR7VqyiExY5YfbYrKG4ULS+SayBzhxlwwymiZsWR8qBpP7T1WlZ RCIOmsWUKoVFxqqaJ51sjRNNJZz9NNzx+grzVxUJNCJv3fDfvohMa/5ySlcabJYk ucmYoUjNXU1l/oUW0JC0vilEeoVEGtfEdevzx/h3RJbx7QKP373kMycGWrwF5o5H wWxlQ06wthLfB6b7Zl4LXfIJAlL5yXvhVqC+z6JAvutAhRApGP8rwC10FHKng6ca fMQQL7K34AaXWQczpchMfpKl8e7Oyo7M9yZjR7wnw0HH4ykhCWZrA6F4cyTaB2P/ oDNjYu4nbsNek3XUPa104x/qqy2RupA9cFQDxxjPpDo0IOyNAlRVdA2X5dsMsD2L tCk/kUYv =fJ9u -----END PGP SIGNATURE-----0501a73078e4aaca2663f38de0a2397c8e6d8189f30b42bbec7d4e894bd0377766Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.