A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Apply the security best practices from the Red Hat OpenShift Dev Spaces Administration Guide: https://docs.redhat.com/en/documentation/red_hat_openshift_dev_spaces/3.24/html/administration_guide/security-best-practices

History

Tue, 13 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 15:45:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.
Title github.com/che-incubator/che-code: Eclipse Che — unauthenticated RCE and secret exfiltration via TCP/3333 Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333
First Time appeared Redhat
Redhat openshift Devspaces
CPEs cpe:/a:redhat:openshift_devspaces:3.22::el9
cpe:/a:redhat:openshift_devspaces:3.23::el9
cpe:/a:redhat:openshift_devspaces:3.24::el9
cpe:/a:redhat:openshift_devspaces:3:
Vendors & Products Redhat
Redhat openshift Devspaces
References

Tue, 02 Dec 2025 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title github.com/che-incubator/che-code: Eclipse Che — unauthenticated RCE and secret exfiltration via TCP/3333
Weaknesses CWE-306
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-01-13T15:51:21.791Z

Reserved: 2025-10-31T14:14:59.157Z

Link: CVE-2025-12548

cve-icon Vulnrichment

Updated: 2026-01-13T15:51:16.262Z

cve-icon NVD

Status : Received

Published: 2026-01-13T16:15:55.527

Modified: 2026-01-13T16:15:55.527

Link: CVE-2025-12548

cve-icon Redhat

Severity : Important

Publid Date: 2025-12-02T07:07:00Z

Links: CVE-2025-12548 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses