Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.
References
| Link | Resource |
|---|---|
| https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-8r4f-65cr-fwxm | Vendor Advisory |
| https://www.vulncheck.com/advisories/ghidra-sql-injection-via-unescaped-filter-values-in-bsim-search | Third Party Advisory |
| https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-8r4f-65cr-fwxm | Vendor Advisory |
Configurations
History
11 Jun 2026, 13:58
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:* | |
| First Time |
Nsa ghidra
Nsa |
|
| References | () https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-8r4f-65cr-fwxm - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/ghidra-sql-injection-via-unescaped-filter-values-in-bsim-search - Third Party Advisory |
10 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-8r4f-65cr-fwxm - |
10 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-10 14:16
Updated : 2026-06-11 13:58
NVD link : CVE-2026-52758
Mitre link : CVE-2026-52758
CVE.ORG link : CVE-2026-52758
JSON object : View
Products Affected
nsa
- ghidra
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
