Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database. | |
| Title | Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search | |
| First Time appeared |
Nsa
Nsa ghidra |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nsa
Nsa ghidra |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T13:41:02.636Z
Reserved: 2026-06-08T15:20:09.274Z
Link: CVE-2026-52758
Updated: 2026-06-10T13:40:03.467Z
Status : Received
Published: 2026-06-10T14:16:36.170
Modified: 2026-06-10T15:16:41.307
Link: CVE-2026-52758
No data.
OpenCVE Enrichment
Updated: 2026-06-10T15:00:13Z