9.8
CVSSv3

CVE-2023-22671

Published: 06/01/2023 Updated: 12/01/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra up to and including 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nsa ghidra