CVE-2026-4946Disclosure(nsa / ghidra)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch nsa ghidra systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotation (which is intended for trusted, user-authored comments) is also parsed in comments generated during auto-analysis (such as CFStrings in Mach-O binaries). This allows a crafted binary to present seemingly benign clickable text which, when clicked, executes attacker-controlled commands on the analyst’s machine.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ghidra

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-29); latest day: 2
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
ghidra

Deep dive

Activity timeline7 mentions / 4d
01122Mentions · 2026-03-29: 2Mentions · 2026-03-30: 2Mentions · 2026-03-31: 1Mentions · 2026-04-02: 2PoC Mentioned / Linked · 2026-03-30: 1PoC Mentioned / Linked · 2026-03-31: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-03-29: 2Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 1Technical Details · 2026-04-02: 203-2903-3003-3104-02
Signal classification3 categories
Disclosure
342.9%
Patch
228.6%
PoC
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-292
Disclosure1Patch1
2026-03-302
Disclosure1PoC1
2026-03-311
PoC1
2026-04-022
Disclosure1Patch1
Full discourse7 posts
  • solst/ICE of Astarte@IceSolst
    PoC

    RCE in Ghidra: My fav bugs target security tools. In CVE-2026-4946, you can embed these into your binary, analyst loads binary, Ghidra auto-generates the comments, analyst clicks on it, command executes. Write-up: https://takeonme.org/cves/cve-2026-4946/ https://t.co/n5YKGsGRmH

    Post summary

    The tweet reveals a remote code execution flaw (CVE‑2026‑4946) in Ghidra, describing how malicious embedded strings trigger command execution via auto‑generated comments, and links to a write‑up containing the PoC.

    855635716722.4K
    31.0K followersView on X
  • Mr. OS@ksg93rd
    PoC

    #exploit #AppSec 1⃣ CVE-2026-4946: https://takeonme.org/cves/cve-2026-4946 NSA Ghidra Auto-Analysis Annotation Command Execution // A novel and highly effective attack against reverse engineers and malware analysts. By embedding malicious annotation payloads into distributed binaries, an attacker can reliably achieve code execution on the systems of analysts who inspect those binaries in Ghidra 2⃣ CVE-2025-14325: https://qriousec.github.io/post/cve-2025-14325/ SpiderMonkey Type Confusion in Baseline JIT Inline Cache // A type confusion in SpiderMonkey's JIT inline cache that enables arbitrary memory access and RCE through heap leaks and memory overlapping exploits during property operations

    Post summary

    Two CVEs – one in Ghidra’s auto‑analysis annotations and another in SpiderMonkey’s JIT – are highlighted with proof‑of‑concept exploitation details; however, no active exploitation or patch information is provided.

    01021249
    3.2K followersView on X
  • Michael Martino@battista212
    Disclosure

    CVE-2026-4946 (CVSS 8.8) is command injection vulnerability in NSA Ghidra. Threat actors can embed payloads directly into compiled binaries that render as innocuous clickable labels like View License, triggering arbitrary command execution when analyst clicks them.

    Post summary

    The post announces CVE-2026-4946, a high‑severity command injection flaw in NSA Ghidra, detailing how attackers could embed malicious payloads inside compiled binaries that trigger arbitrary command execution through seemingly benign clickable labels.

    1000045
    187 followersView on X
  • bigmacd@bigmacd16684
    Patch

    CVE-2026-4946 (CVSS 8.8, CWE-78) is a command injection vulnerability in NSA Ghidra versions before 12.0.3. The {@execute} directive from user comments is also applied to auto-escaping. Update to version 12.0.3 to stay secure. #NSAG

    Post summary

    CVE-2026-4946 is a command injection vulnerability in NSA Ghidra (pre‑12.0.3); users are advised to upgrade to version 12.0.3 to mitigate the risk.

    1000021
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4946 Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when … https://www.cve.org/CVERecord?id=CVE-2026-4946

    Post summary

    The post discloses that Ghidra versions prior to 12.0.3 are vulnerable to arbitrary command execution via improperly processed annotation directives, but it provides no PoC, exploitation evidence, or patch details.

    00010101
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4946 - High Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts wit... https://www.thehackerwire.com/vulnerability/CVE-2026-4946/ https://t.co/cFTioYi4rk

    Post summary

    The text announces a high‑severity vulnerability (CVE‑2026‑4946) in Ghidra versions prior to 12.0.3, detailing arbitrary command execution via annotation directives during binary analysis.

    0000066
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-4946: HIGH] Warning: Ghidra versions before 12.0.3 are vulnerable to arbitrary command execution via crafted annotation directives in binary data when interacting with the UI. Upgrade to the latest v...#cve,CVE-2026-4946,#cybersecurity https://cvefind.com/CVE-2026-4946

    Post summary

    The message warns of a high‑severity CVE in earlier Ghidra versions and advises upgrading to mitigate the arbitrary command execution vulnerability.

    0000071
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnsaghidra---

Explore more