Server-side Request Forgery (SSRF) Affecting @theia/core package, versions <1.73.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-THEIACORE-17810718
  • published3 Jul 2026
  • disclosed3 Jul 2026
  • creditZyy0530, 7thParkk, mauriceng98

Introduced: 3 Jul 2026

NewCVE-2026-10055  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade @theia/core to version 1.73.0 or higher.

Overview

@theia/core is a the main extension for all Theia-based applications, and provides the main framework for all dependent extensions.

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the request-service process. An attacker can access sensitive internal resources by sending crafted URLs to the backend, which then performs server-side HTTP requests and returns the responses. This can expose internal administrative endpoints, cloud instance metadata services, and other resources not intended to be accessible from the client. This is only exploitable if the service connection is reachable by untrusted users, such as in multi-tenant or publicly accessible deployments.

CVSS Base Scores

version 4.0
version 3.1