CVE-2026-52758

Source
https://cve.org/CVERecord?id=CVE-2026-52758
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52758.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-52758
Aliases
  • GHSA-8r4f-65cr-fwxm
Published
2026-06-10T12:42:30Z
Modified
2026-08-12T03:51:49Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search
Details

Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers can inject arbitrary SQL via the BSim network query protocol to read, modify, or delete data in the PostgreSQL database.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52758.json"
}
References

Affected packages

Git / github.com/nationalsecurityagency/ghidra

Affected ranges

Type
GIT
Repo
https://github.com/nationalsecurityagency/ghidra
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "11.0"
        },
        {
            "fixed": "12.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52758.json"