8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.
AI Analysis
SQL injection vulnerability in BSim filter types due to unescaped user input
Basic Information
ID
CVE-2026-52758
Source
VulnCheck
Published
Jun 10, 2026 at 12:42
Affected Product
Vendor
nationalsecurityagency
Product
ghidra
Version
11.0
Affected Versions
nationalsecurityagency ghidra 11.0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
National Security Agency
Product
Ghidra
Version
11.0