PT-2026-48416 · Ghidra · Ghidra
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Ghidra versions prior to 12.2
Description
The IsfServer accepts TCP connections and passes client-supplied namespace strings directly to filesystem operations without validation, leading to an unauthenticated path traversal. Remote attackers can connect to port '54321' and send crafted protobuf messages containing traversal sequences to enumerate filesystem paths and probe arbitrary files.
Recommendations
Update to version 12.2 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghidra