We use cookies to improve your experience on our site.
AVID-2026-R0414
Description
Eclipse Theia IDE MCP Configuration Code Execution
Details
The Eclipse Theia IDE automatically loads MCP configurations from the .theia\settings.json file upon opening a source code directory. This file can contain arbitrary code that will execute without any further user interaction.
References
Affected or Relevant Artifacts
- Developer: Eclipse
- Deployer:
- Artifact Details:
| Type | Name |
|---|---|
| System | Theia IDE |
Impact
- (none)
Other information
- Report Type: Advisory
- Credits: Aaron Portnoy, Mindgard
- Date Reported: 2025-11-18
- Version: 0.3.1
- AVID Entry