{"id":"CVE-2025-12548","title":"A flaw was found in Eclipse Che che-machine-exec","summary":"A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unau…","severity":"critical","cvss":9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-306"],"vendor":"Red Hat","product":"devspaces/code-rhel9","affected":["devspaces/code-rhel9 (all versions)","devspaces/code-rhel9 (all versions)","devspaces/code-rhel9 (all versions)"],"published":"2026-01-13","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:17:24.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-12548","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:22620","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:22623","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:22652","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-12548","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2408850","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-12548.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-12548"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12548"}],"tags":["nvd","exploit-available","cve.org","csaf","vex","red-hat"],"epss":0.01328,"epssPercentile":0.69795,"exploits":{"metasploit":["exploit/linux/http/eclipse_che_machine_exec_rce"],"checkedAt":"2026-09-24T07:52:55.169Z"},"exploitAvailable":true,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-01-13T15:51:02.077067Z"},"ingestedAt":"2026-09-21T16:49:07.875Z","patched":["openshift_dev_spaces_rhosds 3.22","openshift_dev_spaces_rhosds 3.23","openshift_dev_spaces_rhosds 3.24"],"slug":"CVE-2025-12548","body":"## Overview\n\nA flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2025:22620** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces (RHOSDS) 3.22 · released 2025-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2025:22620)\n- **RHSA-2025:22652** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces (RHOSDS) 3.23 · released 2025-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2025:22652)\n- **RHSA-2025:22623** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces (RHOSDS) 3.24 · released 2025-12-02 · [advisory](https://access.redhat.com/errata/RHSA-2025:22623)","depth":"abyssal","depthScore":62,"depthScoreParts":{"impact":49.5,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[]}