📦

ghidra

Vendor: nsa

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 4 Remote Access
Total CVEs 23 Total Indexed
Avg. EPSS 1.45% Exploit Prob.
Latest CVE CVE-2026-52759 Jun 10

Security Vulnerability Index

Page 3 / 3
7.8 CVSS
CVE-2019-13623
Exploit Found

In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attackers to overwrite arbitrary files in scenarios where an intermediate analysis result is archived for sharing with other persons. To achieve arbitrary code execution, one approach is to overwrite some critical Ghidra modules, e.g., the decompile module.

EPSS: 2.35%