This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Suriq - Always on Watch
suriq.io
did:plc:6vjp7fbgz5ductueireifliv
Opening a booby-trapped code repository can run an attacker's commands in editors built on Eclipse Theia (the framework under Arduino IDE 2.x and other tools).
A crafted git config runs on folder open, no trust prompt. CVE-2026-19884, CVSS 8.4.
Fix: update to Theia 1.70.0.
https://suriq.io/blog/eclipse-theia-repo-open-command-execution-cve-2026-19884
2026-08-14T16:02:48.566Z