CVE-2026-49497
LOW
NVD
CVSS Score
3.3
Severity
LOW
Published
Jun 10, 2026
Vendor
unknown
Description
Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames from ELF binary .gnu_debuglink sections before constructing file paths. Attackers can craft malicious ELF binaries with traversal sequences to probe filesystem existence and leak CRC32 hashes of arbitrary files during automatic DWARF analysis.