CVE-2025-12548

CRITICAL

CVSS v3

9

CRITICAL

EPSS Score

43.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

Technical Details

CVSS v3 Vector
3.1
Published
1/13/2026
Last Modified
4/14/2026

Frequently Asked Questions

What is CVE-2025-12548?

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

Is CVE-2025-12548 actively exploited?

Active exploitation of CVE-2025-12548 has not been confirmed. The EPSS score is 43.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-12548?

CVE-2025-12548 has a CVSS v3 base score of 9 (CRITICAL severity), with vector string 3.1.

Is CVE-2025-12548 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.