Vulnerability Description
Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim uses an attacker-supplied .i64 file.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://blog.calif.io/p/using-ida-to-find-bugs-in-ida-with
- https://docs.hex-rays.com/release-notes/9_3sp2
FAQ
What is CVE-2026-45181?
CVE-2026-45181 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim u...
How severe is CVE-2026-45181?
CVE-2026-45181 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45181?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.