CVE-2025-12548
CRITICALEclipse Che - RCE
Title source: llmDescription
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.
References (5)
Scores
CVSS v3
9.0
EPSS
0.0032
EPSS Percentile
54.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Classification
CWE
CWE-306
Status
draft
Timeline
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026