A vulnerability was found in Eclipse Theia up to 1.73.x. It has been classified as problematic. This issue affects some unknown processing of the component HTTP Middleware. Performing a manipulation results in path traversal.

This vulnerability is identified as CVE-2026-61891. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.