CVE-2025-12548

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-13 16:15

Updated : 2026-01-14 16:26


NVD link : CVE-2025-12548

Mitre link : CVE-2025-12548

CVE.ORG link : CVE-2025-12548


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function