Executive brief
Ghidra, a popular software reverse-engineering suite, is vulnerable to a security flaw in its theme import feature. An attacker can trick a user into importing a specially crafted theme file that silently writes malicious files to the user's computer. This could allow an attacker to gain full control of the system or steal sensitive data by overwriting critical configuration files.
Technical details
A path traversal vulnerability (Zip Slip) exists in Ghidra's theme import logic within 'ThemeUtils.java'. When a user imports a ZIP-based theme via the GUI, the application fails to validate that the entry names within the ZIP file do not contain traversal sequences (e.g., '../'). An attacker can craft a malicious ZIP file that, when imported, writes files to arbitrary locations on the filesystem where the user has write permissions. This can be leveraged for remote code execution by overwriting sensitive files such as '.bashrc' or adding keys to '.ssh/authorized_keys'. The vulnerability is addressed in version 12.0.4 by implementing path validation using 'FileUtilities.isPathContainedWithin()'.
Affected products
- NSA Ghidra < 12.0.4
Timeline
- 2026-03-10: advisory: Initial GitHub Security Advisory published
- 2026-06-10: disclosed: CVE published and NVD record created
- 2026-06-10: patched: Fix released in version 12.0.4