ZeroHour

CVE-2026-78299

niche

Path Traversal in Eclipse Embedded CDT CMSIS-Pack Extraction (6.0–6.7)

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

Eclipse Embedded CDT versions 6.0 through 6.7 contain a path traversal flaw (CWE-22, CVSS 9.1 critical) in how CMSIS-Pack archives are extracted: when a developer installs a CMSIS pack, entries in the archive can escape the intended installation directory and write arbitrary files to other locations on disk. The flaw is triggered when the tool extracts a compromised or malicious CMSIS pack, so exploitation depends on a supply-chain foothold (e.g., a tampered pack on a repository or redirected download) rather than direct targeting of the developer's machine. A successful attack gives the attacker arbitrary file writes with the developer's privileges, which can overwrite binaries, configuration, or startup files and plausibly lead to code execution plus theft of source code and credentials on developer workstations and CI build systems. Anyone using Eclipse Embedded CDT 6.0–6.7 to install CMSIS packs is affected. No public proof of concept or in-the-wild exploitation is known, and the issue is not on the CISA KEV list.

What to do: Upgrade to the latest Eclipse Embedded CDT release, i.e., any version newer than 6.7. Only install CMSIS packs from trusted, verified sources and validate publisher signatures or checksums before extraction. On machines that imported third-party or unverified packs, check for unexpected files written outside the pack installation directory (for example in the user home directory or startup locations).

Affected
Eclipse Foundation Eclipse Embedded CDT (Embedded C/C++ Development Tools)6.0 through 6.7
Estimated exposure
nichelow tens of thousands of developers at most (no reliable install counts) — Eclipse Embedded CDT is a specialized open-source Eclipse plugin suite for embedded ARM/RISC-V C/C++ development with no published active-install metrics, which bounds plausible exposure to that niche developer population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.

Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.