Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block...
Moderate severity
Unreviewed
Published
May 10, 2026
to the GitHub Advisory Database
•
Updated May 10, 2026
Description
Published by the National Vulnerability Database
May 9, 2026
Published to the GitHub Advisory Database
May 10, 2026
Last updated
May 10, 2026
Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directry if the victim uses an attacker-supplied .i64 file.
References