CVE-2026-78299
nichePath Traversal in Eclipse Embedded CDT CMSIS-Pack Extraction (6.0–6.7)
Eclipse Embedded CDT versions 6.0 through 6.7 contain a path traversal flaw (CWE-22, CVSS 9.1 critical) in how CMSIS-Pack archives are extracted: when a developer installs a CMSIS pack, entries in the archive can escape the intended installation directory and write arbitrary files to other locations on disk. The flaw is triggered when the tool extracts a compromised or malicious CMSIS pack, so exploitation depends on a supply-chain foothold (e.g., a tampered pack on a repository or redirected download) rather than direct targeting of the developer's machine. A successful attack gives the attacker arbitrary file writes with the developer's privileges, which can overwrite binaries, configuration, or startup files and plausibly lead to code execution plus theft of source code and credentials on developer workstations and CI build systems. Anyone using Eclipse Embedded CDT 6.0–6.7 to install CMSIS packs is affected. No public proof of concept or in-the-wild exploitation is known, and the issue is not on the CISA KEV list.
What to do: Upgrade to the latest Eclipse Embedded CDT release, i.e., any version newer than 6.7. Only install CMSIS packs from trusted, verified sources and validate publisher signatures or checksums before extraction. On machines that imported third-party or unverified packs, check for unexpected files written outside the pack installation directory (for example in the user home directory or startup locations).
| Eclipse Foundation Eclipse Embedded CDT (Embedded C/C++ Development Tools) | 6.0 through 6.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.