CVE-2026-78299
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/747, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78299.json, https://github.com/eclipse-embed-cdt/eclipse-plugins/security/advisories/GHSA-qch4-8rmp-mjx3, https://nvd.nist.gov/vuln/detail/CVE-2026-78299