PT-2026-48415 · Ghidra · Ghidra
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ghidra versions prior to 12.0.4
Description
A path traversal issue exists in the theme import functionality. This allows attackers to write files outside the intended theme directory by using malicious theme ZIP files containing traversal sequences in filenames. This can lead to the modification of sensitive files, such as
.bashrc or .ssh/authorized keys, or the execution of arbitrary code.Recommendations
Update to version 12.0.4 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghidra