PT-2026-48416 · Ghidra · Ghidra

·

CVE-2026-52756

·

Published

2026-06-10

·

Updated

2026-06-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ghidra versions prior to 12.2
Description The IsfServer accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations without validation, leading to an unauthenticated path traversal. Remote attackers can connect to port '54321' and send crafted protobuf messages containing traversal sequences to enumerate filesystem paths and probe arbitrary files.
Recommendations Update to version 12.2 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52756
GHSA-8PR2-46MF-V2R2

Affected Products

Ghidra