Vulnerability Description
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nsa | Ghidra | >= 11.0, < 12.1 |
Related Weaknesses (CWE)
References
- https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-8r4f-6Vendor Advisory
- https://www.vulncheck.com/advisories/ghidra-sql-injection-via-unescaped-filter-vThird Party Advisory
- https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-8r4f-6Vendor Advisory
FAQ
What is CVE-2026-52758?
CVE-2026-52758 is a vulnerability with a CVSS score of 8.8 (HIGH). Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers ca...
How severe is CVE-2026-52758?
CVE-2026-52758 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-52758?
Check the references section above for vendor advisories and patch information. Affected products include: Nsa Ghidra.