CVE 8.7 HIGH

Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search_CVE-2026-52758

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.

AI Analysis

SQL injection vulnerability in BSim filter types due to unescaped user input

Basic Information

ID CVE-2026-52758
Source VulnCheck
Published Jun 10, 2026 at 12:42

Affected Product

Vendor nationalsecurityagency
Product ghidra
Version 11.0
Affected Versions nationalsecurityagency ghidra 11.0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor National Security Agency
Product Ghidra
Version 11.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.