CVE-2025-12548: Red Hat Openshift Dev Spaces Rhosds 3.22
Critical severity, CVSS 9.0. EPSS: 1.3% chance of exploitation in the next 30 days.
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.
Affected products
- Red Hat Red Hat Openshift Dev Spaces Rhosds 3.22: before 3.22.1-1763525702 (fixed in 3.22.1-1763525702)
- Red Hat Red Hat Openshift Dev Spaces Rhosds 3.23: before 3.23.1-1763508770 (fixed in 3.23.1-1763508770)
- Red Hat Red Hat Openshift Dev Spaces Rhosds 3.24: before 3.24.1-1763547630 (fixed in 3.24.1-1763547630)
Published 2026-01-13. Last modified 2026-09-21.