Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-78299: Eclipse Embedded CDT can write files anywhere via malicious pack
CVE-2026-78299 · published 26 days ago
Summary
Versions 6.0 through 6.7 of Eclipse Embedded CDT may extract a specially crafted CMSIS pack and place files outside the intended folder. This could let an attacker create or overwrite any file on the computer, potentially taking control of the system. Update to a newer version of Eclipse Embedded CDT or use only trusted CMSIS packs to mitigate the risk.
What to do
- Update eclipse foundation eclipse embedded cdt (c/c++ development tools) to version 6.8.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| eclipse foundation | eclipse embedded cdt (c/c++ development tools) | < 6.8.0 |
Original advisory text
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing o...
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
References
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/747
- https://github.com/eclipse-embed-cdt/eclipse-plugins/security/advisories/GHSA-qc...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78299... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-78299 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-22Path Traversal
Timeline
Published14 Sep 2026
Updated7 Oct 2026
First seen14 Sep 2026
Track software like this
Free during beta