CVE-2026-78299

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 13:18

Updated : 2026-09-14 20:16


NVD link : CVE-2026-78299

Mitre link : CVE-2026-78299

CVE.ORG link : CVE-2026-78299


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')