{"id":"CVE-2026-78299","details":"In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.","aliases":["GHSA-qch4-8rmp-mjx3"],"modified":"2026-09-16T03:47:23.987824474Z","published":"2026-09-14T12:59:14.849Z","database_specific":{"cna_assigner":"eclipse","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78299.json"},"references":[{"type":"WEB","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/747"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78299.json"},{"type":"ADVISORY","url":"https://github.com/eclipse-embed-cdt/eclipse-plugins/security/advisories/GHSA-qch4-8rmp-mjx3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78299"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eclipse-embed-cdt/eclipse-plugins","events":[{"introduced":"d1356bd492887ee169c84061cfbfd9be9e773ee1"},{"fixed":"0f6f231872f6c6af65cad7a05146684dfa0a8f15"}],"database_specific":{"extracted_events":[{"introduced":"6.0.0"},{"fixed":"6.8.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v6.8.0-202608251538","v6.7.0","v6.7.0-202602251544","v6.6.1-202408270735","v6.6.1","v6.6.0","v6.6.0-202404031712","v6.5.0","v6.4.0","v6.4.0-202307251916","v6.3.2","v6.3.2-202304281106","v6.3.1","v6.3.1-202210101738","v6.3.0-202208180721","v6.3.0","v6.2.2","v6.2.2-202206121057","v6.2.1-202204041943","v6.2.1","v6.1.2","v6.1.2-202102181132","v6.1.1","v6.1.0","v6.1.0-202101081915","v6.1.0-202101060807","v6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78299.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}