CVE-2026-45181

Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim uses an attacker-supplied .i64 file.
Configurations

No configuration.

History

10 May 2026, 08:16

Type Values Removed Values Added
Summary (en) Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directry if the victim uses an attacker-supplied .i64 file. (en) Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim uses an attacker-supplied .i64 file.

09 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-09 22:16

Updated : 2026-05-13 15:46


NVD link : CVE-2026-45181

Mitre link : CVE-2026-45181

CVE.ORG link : CVE-2026-45181


JSON object : View

Products Affected

No product.

CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')