In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 13:18
Updated : 2026-09-14 20:16
NVD link : CVE-2026-78299
Mitre link : CVE-2026-78299
CVE.ORG link : CVE-2026-78299
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
