SB2026051604 - Path traversal in Ghidra Debugger ISF server
Published: May 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Path traversal (CVE-ID: N/A)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in Debugger ISF Server when processing client-supplied namespace strings over TCP connections. A remote attacker can send a specially crafted protobuf request to disclose sensitive information.
User interaction is required because the server must first be manually launched, and differential error responses can reveal whether targeted filesystem paths exist.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.