PT-2026-48408 · Ghidra · Ghidra

·

CVE-2026-49497

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ghidra versions prior to 12.1
Description A path traversal issue exists in the SameDirDebugInfoProvider component. The software fails to validate filenames extracted from the .gnu debuglink sections of ELF binaries before constructing file paths. This allows an attacker to use malicious ELF binaries containing traversal sequences to probe for the existence of files on the filesystem and leak CRC32 hashes of arbitrary files during automatic DWARF analysis (a process used to read debugging information from binaries).
Recommendations Update to version 12.1 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49497
GHSA-57G6-7QW2-P5HX

Affected Products

Ghidra