Security Advisory

CVE-2026-45181

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-09 21:47:35
Last updated 2026-05-11 14:59:22
Assigner mitre
CVSS score 6.5
State PUBLISHED

Description

Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directory if the victim uses an attacker-supplied .i64 file.