Junglewise Threat Intelligence

CVE-2025-12548: Eclipse Che che-machine-exec unauthenticated remote code execution

CVE-2025-12548 · Severity: critical · CVSS 9 · Published 2026-01-13

Vendors: Eclipse.

Executive brief

Eclipse Che is a development environment platform used by organizations to provide developers with cloud-based workspaces. A critical vulnerability in its che-machine-exec component allows unauthenticated attackers to execute arbitrary commands and steal secrets (SSH keys, tokens) from developer workspace containers by exploiting an exposed JSON-RPC API, potentially compromising developer credentials and sensitive data across multiple users.

Technical details

The vulnerability is an unauthenticated remote code execution flaw in Eclipse Che's che-machine-exec component, stemming from an exposed JSON-RPC/WebSocket API listening on TCP port 3333 without proper authentication. An unauthenticated remote attacker can directly interact with this API to execute arbitrary commands within Developer Workspace containers and exfiltrate secrets including SSH keys and authentication tokens stored in other users' containers. The attack vector is network-based and requires no authentication or user interaction. Red Hat addressed this in OpenShift Dev Spaces 3.22.1 released on 2025-12-02.

Affected products

  • Eclipse Che affected versions prior to fix in Red Hat OpenShift Dev Spaces 3.22.1

Timeline

  • 2025-12-02: disclosed: Red Hat security advisory RHSA-2025:22620 issued
  • 2025-12-02: patched: Fix released in Red Hat OpenShift Dev Spaces 3.22.1

References

Related threats