CVE-2026-52758

HIGH

Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search

Title source: cna
STIX 2.1

Description

Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-8r4f-65cr-fwxm)
https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-8r4f-65cr-fwxm

Scores

CVSS v3 8.8
EPSS 0.0031
EPSS Percentile 22.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (3)
nationalsecurityagency/ghidra 11.0 - 12.1
nationalsecurityagency/ghidra 12.1
nsa/ghidra 11.0 - 12.1
Published Jun 10, 2026
Tracked Since Jun 10, 2026