<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Spring Tools for Theia - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/spring-tools-for-theia/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 30 Jul 2026 15:30:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/spring-tools-for-theia/feed.xml" rel="self" type="application/rss+xml"/><item><title>Critical Vulnerabilities in Spring Tools IDE Extensions</title><link>https://feed.craftedsignal.io/briefs/2026-07-spring-tools-vulnerabilities/</link><pubDate>Thu, 30 Jul 2026 15:30:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-spring-tools-vulnerabilities/</guid><description>Multiple vulnerabilities in Spring Tools for Eclipse and VSCode/Cursor/Theia allow for remote code execution, unauthorized service access, credential exposure, and cross-site scripting.</description><content:encoded><![CDATA[<p>VMware has released a security advisory (AV26-759) detailing six vulnerabilities affecting Spring Tools for Eclipse (versions &lt;= 5.2.0) and Spring Tools for VSCode, Cursor, and Theia (versions &lt;= 2.2.0). The vulnerabilities range from critical Remote Code Execution (RCE) flaws to information disclosure and Cross-Site Scripting (XSS).</p>
<p>The most severe issue, CVE-2026-47858, allows for RCE via live information startup mode. Additionally, CVE-2026-47873 exposes JDWP and JMX ports on all network interfaces, providing a pathway for unauthenticated remote access to debugging and management interfaces. Other identified issues include the use of a non-cryptographic PRNG for DevTools remote secrets (CVE-2026-47882), plaintext logging of HTTP proxy credentials (CVE-2026-59326), insecure local storage of secrets in Eclipse launch configurations (CVE-2026-59327), and XSS in dependency tooltips (CVE-2026-59328). Organizations using these developer tools should prioritize updating to the latest versions to mitigate these risks.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could result in full system compromise, unauthorized access to developer environments, theft of sensitive credentials (proxy and remote secrets), and potential for lateral movement within a development network. These flaws directly impact the integrity and confidentiality of developer workstations and the software build pipelines they support.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update Spring Tools for Eclipse to the latest version immediately to remediate CVE-2026-47858, CVE-2026-47873, CVE-2026-47882, CVE-2026-59326, CVE-2026-59327, and CVE-2026-59328.</li>
<li>Update Spring Tools for VSCode, Cursor, and Theia to the latest version to address these vulnerabilities.</li>
<li>Audit developer workstations for insecure IDE configurations, particularly regarding exposed JDWP/JMX ports.</li>
<li>Rotate any credentials that may have been logged in plaintext or stored insecurely due to CVE-2026-59326 and CVE-2026-59327.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>ide</category><category>rce</category><category>spring-framework</category></item></channel></rss>