VendorsNSAghidraall versions
Vulnerabilities

NSA Ghidra

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2019-16941
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call).
Published 2019-09-28 · Modified
9.8EPSS 0.051
CVE-2023-22671
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
Published 2023-01-06 · Modified
9.8EPSS 0.029
CVE-2019-13625
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.
Published 2019-07-17 · Modified
9.4EPSS 0.024
CVE-2026-52751
Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection
Published 2026-06-10 · Analyzed
8.8EPSS 0.011
CVE-2026-4946
NSA Ghidra Auto-Analysis Annotation Command Execution
Published 2026-03-29 · Analyzed
8.8EPSS 0.008
CVE-2026-52758
Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search
Published 2026-06-10 · Analyzed
8.8EPSS 0.006
CVE-2026-49498
Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescaped Username
Published 2026-06-10 · Analyzed
8.8EPSS 0.005
CVE-2026-52754
Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule
Published 2026-06-10 · Analyzed
8.8EPSS 0.005
CVE-2026-52750
Ghidra < 12.1- Command Injection via URL Annotation Click
Published 2026-06-10 · Analyzed
8.4EPSS 0.007
CVE-2026-52755
Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Import
Published 2026-06-10 · Analyzed
8.4EPSS 0.002
CVE-2026-52752
Ghidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry Names
Published 2026-06-10 · Analyzed
8.4EPSS 0.002
CVE-2019-13623
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis result is archived for sharing with other persons. To achieve arbitrary code execution, one approach is to overwrite some critical Ghidra modules, e.g., the decompile module.
Published 2019-07-17 · Modified
7.81 PoCEPSS 0.050
CVE-2019-17665
NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory.
Published 2019-10-16 · Modified
7.8EPSS 0.005
CVE-2019-17664
NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path, the Java process working directory is set to this path. Then, when launching the Python interpreter via the "Ghidra Codebrowser > Window > Python" option, Ghidra will try to execute the cmd.exe program from this working directory.
Published 2019-10-16 · Modified
7.8EPSS 0.004
CVE-2026-49496
Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector Reallocation
Published 2026-06-10 · Analyzed
6.9EPSS 0.002
CVE-2026-52759
Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mach-O Parser
Published 2026-06-10 · Analyzed
6.7EPSS 0.002
CVE-2026-52753
Ghidra < 12.0.3 - Out-of-Memory in Rust Symbol Demangler via Malformed Symbol
Published 2026-06-10 · Analyzed
6.7EPSS 0.002
CVE-2026-49495
Ghidra 10.2 < 12.1 - Denial of Service via Circular Reference in Mach-O Export Trie Parser
Published 2026-06-10 · Analyzed
6.7EPSS 0.002
CVE-2026-52756
Ghidra < 12.2 - Unauthenticated Path Traversal in Debugger ISF Server
Published 2026-06-10 · Analyzed
6.5EPSS 0.006
CVE-2026-49497
Ghidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug File Resolution
Published 2026-06-10 · Analyzed
4.6EPSS 0.002
CVE-2026-52757
Ghidra < 12.1 - Heap-use-after-free in HighVariable::merge() during decompilation
Published 2026-06-10 · Analyzed
4.6EPSS 0.002
CVE-2024-58350
Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Order
Published 2026-06-10 · Analyzed
4.0EPSS 0.001