Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
- https://github.com/NationalSecurityAgency/ghidra/issues/4869
No PoCs found on GitHub currently.