CVE-2026-45181 Details
Description
Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim uses an attacker-supplied .i64 file.
A vulnerability exists in Hex-Rays IDA Pro versions 9.2 and 9.3 prior to 9.3sp2, where the application does not properly restrict Clang dependency-file generation. This oversight allows attackers to inject code into a .i64 file, which can then be placed into a plugin directory used by IDA Pro.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 9, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.calif.io/p/using-ida-to-find-bugs-in-ida-with | [email protected] | |
| https://docs.hex-rays.com/release-notes/9_3sp2 | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Hex-Rays IDA Pro | >= 9.2, < 9.3sp2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 10, 2026 | CVE Modified | [email protected] |
| May 9, 2026 | New CVE Received | [email protected] |
Volerion