SB2026051604 - Path traversal in Ghidra Debugger ISF server



SB2026051604 - Path traversal in Ghidra Debugger ISF server

Published: May 16, 2026

Security Bulletin ID SB2026051604
CSH Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Path traversal (CVE-ID: N/A)

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in Debugger ISF Server when processing client-supplied namespace strings over TCP connections. A remote attacker can send a specially crafted protobuf request to disclose sensitive information.

User interaction is required because the server must first be manually launched, and differential error responses can reveal whether targeted filesystem paths exist.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.