External risk intelligence

Eclipse Che Remote Command Execution and Secret Exfiltration Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2025-12548

The vulnerability involves a JSON-RPC/websocket API exposed on a specific TCP port within Eclipse Che, a developer workspace platform. While such services are typically internal, they are often exposed or bridged in enterprise developer environments to allow remote access for distributed teams, making internet-facing exposure a common deployment scenario for this type of service.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security flaw has been identified in Eclipse Che, a developer workspace platform, that could permit unauthorized individuals to execute commands remotely and steal sensitive information like SSH keys and tokens from other users' workspaces. This issue arises from an exposed API that could allow for significant compromise of developer environments.

  • Unauthenticated access to developer workspaces.
  • Impacts remote command execution and data exfiltration.
  • Confirm relevance and exposure within your environment.

Attack Path

How an attacker could exploit the issue

An attacker could reach this vulnerability by sending specially crafted requests to a JSON-RPC or WebSocket API exposed on TCP port 3333. This API is part of Eclipse Che's machine execution component. If successful, an attacker could remotely execute arbitrary commands and steal secrets from other users' developer workspaces without needing any authentication.

  • Unauthenticated remote access to API.
  • Trigger via crafted JSON-RPC/websocket requests.
  • Arbitrary command execution and secret exfiltration.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary commands and exfiltrate sensitive information, such as SSH keys and tokens, from other users' developer workspace containers. This risk exists when the vulnerable JSON-RPC/websocket API is exposed on TCP port 3333.

  • Developer workspace containers and secrets.
  • Via an exposed API on port 3333.
  • Arbitrary command execution and data exfiltration.

Operational Fix

Recommended remediation, mitigation, and detection steps

Understanding ownership and initial triage for this vulnerability requires identifying which teams manage the Eclipse Che platform and its deployed developer workspaces. The primary concern is confirming the exposure of the affected API, assessing its reachability from external networks, and determining the business criticality of affected workspaces to prioritize remediation efforts. Coordination between platform, security, and potentially application teams will be crucial.

  • Platform and Security teams should own this.
  • Verify API reachability and affected workspaces.
  • Plan containment, then vendor-supported remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Eclipse Che and how is it used?

Eclipse Che is a cloud-native developer workspace platform designed to provide browser-based IDEs and consistent, containerized coding environments. Teams use it to standardize development setups, allowing engineers to build and test applications directly within Kubernetes-based workspaces rather than relying on local machine configurations.

What does CWE-306 mean for CVE-2025-12548?

CWE-306 refers to a Missing Authentication for Critical Function weakness. In the context of CVE-2025-12548, it means the software performs sensitive operations—specifically remote command execution and data access—without verifying the identity of the person requesting them. This allows an unauthorized actor to bypass security controls entirely.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending specially crafted JSON-RPC or WebSocket requests to the che-machine-exec component on TCP port 3333. It is important to note that simply having the Eclipse Che software installed does not trigger the bug; the vulnerability requires successful network communication with this specific, exposed API port.

Is my environment at risk according to Halo Surface Signal?

Halo Surface Signal notes that while the vulnerable API on port 3333 is often intended for internal use, it is frequently bridged or exposed in enterprise developer environments to facilitate remote access for distributed teams. You should consider your environment at higher risk if this port is reachable from outside your protected internal network.

What steps should I take to respond to this issue?

Your first step is to identify where your organization runs Eclipse Che and determine if TCP port 3333 is accessible beyond the intended scope. Coordinate with your platform and security teams to verify if these workspaces are internet-facing. Once reachability is assessed, prioritize protecting sensitive data within these workspaces and prepare for vendor-supplied updates.

References