← Vulnerability feed

Vulnerability record · CVE-2026-4946 · published 29 March 2026

CVE-2026-4946: Nsa ghidra os command injection vulnerability

Nsa · Ghidra

Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotation (which is intended for trusted, user-authored comments) is also parsed in comments generated during auto-analysis (such as CFStrings in Mach-O binaries). This allows a crafted binary to present seemingly benign clickable text which, when clicked, executes attacker-controlled commands on the analyst’s machine.

8.8 CVSS 3.1 High EPSS 0.77% · top 46.4% CWE-78 · OS command injection
8.8CVSS 3.1 base score
0.77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 3 tagged exploit
10 Aug 2026Last modified by NVD

Description

Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotation (which is intended for trusted, user-authored comments) is also parsed in comments generated during auto-analysis (such as CFStrings in Mach-O binaries). This allows a crafted binary to present seemingly benign clickable text which, when clicked, executes attacker-controlled commands on the analyst’s machine.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-4946 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22671Nsa ghidra command injection vulnerabilityGhidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when ca…EPSS 2.9%9.8CVE-2019-16941Nsa ghidra xml injection vulnerabilityNSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer i…EPSS 5.1%9.1CVE-2019-13625Nsa ghidra xml external entity (xxe) vulnerabilityNSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.EPSS 2.4%8.7CVE-2026-52758Nsa ghidra sql injection vulnerabilityGhidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries withou…EPSS 0.56%8.7CVE-2026-52754Nsa ghidra improper verification of cryptographic signature vulnerabilityGhidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-sig…EPSS 0.45%8.7CVE-2026-49498Nsa ghidra sql injection vulnerabilityGhidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double…EPSS 0.47%8.6CVE-2026-52751Nsa ghidra deserialization of untrusted data vulnerabilityGhidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated rem…EPSS 1.1%8.4CVE-2026-52750Nsa ghidra argument injection vulnerabilityGhidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly esc…EPSS 0.74%

Source: NIST National Vulnerability Database (record CVE-2026-4946), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.