CVE-2023-22671

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
06/01/2023
Last modified:
07/04/2025

Description

Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:* 10.2.2 (including)