Report: CVE-2026-45181 - Hex-Rays IDA Pro Unrestricted Plugin Directory Access Vulnerability

Report: CVE-2026-45181 - Hex-Rays IDA Pro Unrestricted Plugin Directory Access Vulnerability

CVE ID :CVE-2026-45181 Published : May 9, 2026, 10:16 p.m. | 1 hour ago Description :Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directry if the victim uses an attacker-supplied .i64 file. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
May 9, 2026