CVE-2026-1699 is a GitHub Actions workflow vulnerability in the Eclipse Theia Website repository. The workflow .github/workflows/preview.yml was configured to run on the pull_request_target event and, within that privileged context, checked out and executed code originating from an untrusted pull request. Because pull_request_target runs with the base repository context, the job had access to repository secrets and a highly privileged GITHUB_TOKEN (including contents:write, packages:write, pages:write, actions:write). This unsafe trigger/checkout pattern enabled arbitrary code execution in the repository CI environment under elevated permissions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
GITHUB_TOKEN. This enables exfiltration of secrets, publishing malicious packages under the eclipse-theia organization, modifying the official Theia website (e.g., via Pages), and pushing malicious changes to the repository and/or manipulating Actions artifacts/configuration.If you can’t patch tonight, do this now.
pull_request_target to checkout/build/run untrusted pull request code. Ensure untrusted PR workflows cannot access repository secrets, and explicitly set minimal permissions: for GITHUB_TOKEN (prefer read-only where possible). Apply hardening so PR workflows cannot execute attacker-controlled code with elevated repository context.Patch, then assume compromise.
.github/workflows/preview.yml to avoid executing PR-controlled code in a pull_request_target context (e.g., use pull_request for untrusted PRs, or ensure pull_request_target workflows only operate on trusted code from the base repository and do not checkout/run PR head content). Additionally, reduce GITHUB_TOKEN permissions to least privilege (avoid broad write scopes) and remove/limit secret availability in PR-triggered workflows.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.