Code Injection Vulnerability in Hex-Rays IDA Pro by Hex-Rays
CVE-2026-45181

6.5MEDIUM

Key Information:

Vendor

Hex-rays

Status
Vendor
CVE Published:
9 May 2026

What is CVE-2026-45181?

Hex-Rays IDA Pro versions 9.2 and 9.3 prior to 9.3sp2 are susceptible to a code injection vulnerability due to inadequate handling of Clang dependency-file generation via argument injection. By exploiting this flaw, an attacker can craft a malicious .i64 file, allowing them to inject their code into the plugin directory of the affected system if the victim inadvertently processes this file. This weakness poses a significant threat to users of IDA Pro, as it enables unauthorized code execution and potential system compromise.

Affected Version(s)

IDA 9.2 < 9.3sp2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.