Path traversal in Ghidra - #VU144374

 

Path traversal in Ghidra - #VU144374

Published: August 19, 2026


Vulnerability identifier: #VU144374
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in XmlLoader program XML import (MEMORY_MAP -> MEMORY_CONTENTS) when parsing attacker-supplied program XML files during import. A remote attacker can trick the victim into importing a crafted XML file to disclose sensitive information.

User interaction is required to import the crafted XML file, and valid input must include the declaration for the vulnerable code path to be reached.


Affected software

Ghidra

Remediation

Install security update from vendor's website.

Ghidra - update to 12.1.3

External References

Related Security Bulletins