CVE Feed

    Dashboard / CVE / CVE-2026-4946

    CVE-2026-4946

    Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotation (which is intended for trusted, user-authored comments) is also parsed in comments generated during auto-analysis (such as CFStrings in Mach-O binaries). This allows a crafted binary to present seemingly benign clickable text which, when clicked, executes attacker-controlled commands on the analyst’s machine.

    Published:Mar 29, 2026
    Last Modified:Mar 30, 2026
    EPS:Mar 29, 2026
    EPSS Score:0.00044
    CVSS Score:8.8

    Affected Products

    Vendor
    Nsa
    Product
    Ghidra

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High