Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database. | |
| Title | Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search | |
| First Time appeared |
Nsa
Nsa ghidra |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nsa
Nsa ghidra |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-10T12:42:30.293Z
Updated: 2026-06-10T13:41:02.636Z
Reserved: 2026-06-08T15:20:09.274Z
Link: CVE-2026-52758
No data.
Status : Received
Published: 2026-06-10T14:16:36.170
Modified: 2026-06-10T14:16:36.170
Link: CVE-2026-52758
No data.