
Authorized security-research lab reproducing CVE-2026-1699 (pwn request in preview.yml) — snapshot of eclipse-theia/theia-website
Automated research artifact — not the upstream project.
This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of
eclipse-theia/theia-websiteat commitd272e2418221240a7c9f8480dd0576a65ca49625(2026-01-19), redistributed under that project's own licence, whose file is included unchanged in this snapshot.The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-01-19; see
pinning.mdin the harness output for every change made to the snapshot.Questions or objections: [email protected]
The source for the website and online documentation for the Theia IDE Framework.
Building locally requires node 14.x. Alternatively, you can use to ignore conflicting peer dependencies.
npm i --legacy-peer-depsnpm install && npm run start
To build for production and serve, run:
npm run build
npm run serve
The website is automatically built with Github workflows and deployed on Github pages, which are reachable via theia-ide.org.
A preview of every pull request is published at eclipse-theia/theia-website-previews. You'll see a comment with the link to the preview once the build is finished.
For more information, see publish.yml and preview.yml.
"Theia" is a trademark of the Eclipse Foundation https://www.eclipse.dev/theia