Skip to main content
CRITICAL

CVE-2025-12548

CVSS v3

9

CRITICAL

EPSS Score

43.7 %

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

Technical details

CVSS v3 Vector
3.1
Published
2026-01-13
Last Modified
2026-04-14

Frequently asked questions

What is CVE-2025-12548?

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

Is CVE-2025-12548 actively exploited?

Active exploitation of CVE-2025-12548 has not been confirmed. The EPSS score is 43.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-12548?

CVE-2025-12548 has a CVSS v3 base score of 9 (CRITICAL severity), with vector string 3.1.

Is CVE-2025-12548 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key