CVE-2026-78299

Summary

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.

Affected Software

VendorProductVersion RangeStatus
Eclipse FoundationEclipse Embedded CDT (C/C++ Development Tools)0 < 6.0.0unknown
Eclipse FoundationEclipse Embedded CDT (C/C++ Development Tools)6.0.0 < 6.8.0affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References