Description
Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitrary files outside the intended directory, enabling code execution.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version before 12.0.2
12.0.2 (semver)
Credits
@PrasanthSundararajan69
Fin (@Finder16)
References
github.com/...ghidra/security/advisories/GHSA-jhc2-q7qf-9c25
github.com/...ghidra/security/advisories/GHSA-jhc2-q7qf-9c25 (GitHub Security Advisory (GHSA-jhc2-q7qf-9c25))
www.vulncheck.com/...extension-installer-via-zip-entry-names