PT-2026-48408 · U.S. National Security Agency · Ghidra

Donghwoo Cho

·

Published

2026-06-10

·

Updated

2026-06-10

·

CVE-2026-49497

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu debuglink sections before constructing file paths. Attackers can craft malicious ELF binaries with traversal sequences to probe filesystem existence and leak CRC32 hashes of arbitrary files during automatic DWARF analysis.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-49497

Affected Products

Ghidra