A vulnerability was found in Eclipse Theia up to 1.73.x. It has been classified as problematic. This issue affects some unknown processing of the component HTTP Middleware. Performing a manipulation results in path traversal.
This vulnerability is identified as CVE-2026-61891. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.