Skip to content

Eclipse

Eclipse is the vendor/organization referenced for the affected products Eclipse Theia and Eclipse ThreadX.

Profile source: Mallory opens in a new tab

Eclipse

Family profile

Eclipse is the vendor/organization referenced for the affected products Eclipse Theia and Eclipse ThreadX. The content identifies Eclipse Theia as impacted by CVE-2026-46580, a high-severity prompt injection vulnerability affecting versions prior to 1.71.0, where workspace files matching .prompts/*.prompttemplate could be auto-loaded and used to override or extend AI agent system prompts. The described impact includes potential chaining to data exfiltration via Markdown image rendering and arbitrary command execution via task definitions, with remediation to upgrade to Theia 1.71.0 or later and restrict untrusted workspace features. The content also identifies Eclipse ThreadX as an embedded development suite for resource-constrained devices and notes multiple vulnerabilities in Eclipse ThreadX NetX Duo at git commit 6c8e9d1, including a denial-of-service flaw in the NetX HTTP server and integer underflow vulnerabilities in HTTP server PUT request handling, all triggerable via crafted network traffic. No high-confidence information about Eclipse’s size or location is directly provided in the content.

Operational record

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.