---
id: CVE-2026-78299
title: >-
  In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts
  a compromised CMSIS pack the archive extraction can extract files to locations
  outside of the pack, allowing writing of arbitrary files to other locations on
  …
summary: >-
  In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts
  a compromised CMSIS pack the archive extraction can extract files to locations
  outside of the pack, allowing writing of arbitrary files to other locations on
  …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-22
vendor: Eclipse Foundation
product: Eclipse Embedded CDT (C/C++ Development Tools)
affected:
  - eclipse_embedded_cdt_c_c++_development_tools >= 6.0.0 < 6.8.0
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:38:33.883'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78299'
references:
  - url: >-
      https://github.com/eclipse-embed-cdt/eclipse-plugins/security/advisories/GHSA-qch4-8rmp-mjx3
    label: emo@eclipse.org
  - url: 'https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/747'
    label: emo@eclipse.org
tags:
  - nvd
  - cve.org
epss: 0.00349
epssPercentile: 0.28549
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-14T19:22:43.860977Z'
ingestedAt: '2026-09-14T15:23:07.429Z'
---

## Overview

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
