npm package reportIs @theia/ai-chat safe ? 3 known vulnerabilities, worst severity HIGH.
// reach 0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
// ai model usage Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.
epss chance of exploitation in 30 days, 41st percentile of all CVEs
xyz score CyberXYZ composite out of 10
fig. 01 â GHSA-3jww-hxqj-wfq2, the advisory selected below
// 3 advisories GHSA-3jww-hxqj-wfq2 In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by the AI agent, would cause the agent to follow attacker-controlled instructions (indirect prompt inj HIGH GHSA-m973-pr9r-hp2w In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indire HIGH GHSA-qwjm-9c66-w4q4 In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-co MODE In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by the AI agent, would cause the agent to follow attacker-controlled instructions (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions.
// cvss v4.0 vector CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Attack vector Local
Attack complexity Low
Attack requirements None
Privileges required None
User interaction Active
Confidentiality (vulnerable system) High
Integrity (vulnerable system) High
Availability (vulnerable system) High
Confidentiality (subsequent systems) None
Integrity (subsequent systems) None
Availability (subsequent systems) None Checked 2026-09-26 at 01:06 UTC. The most recent advisory here was published 2026-06-18. Updated continuously from NVD, GHSA, OSV and CNA feeds.
Think a verdict here is wrong? Tell us â we respond within 2 business days. Report an issue with this page