Skip to content

Releases: balcsida/GhydraMCP

Release v3.1.0

Choose a tag to compare

@github-actions github-actions released this 27 Sep 20:14
54a8c30

Fork (balcsida/GhydraMCP) changes on top of upstream 3.0.0-rc.1, ported onto the Javalin server.

Added

  • Multi-file support: every program-scoped endpoint accepts ?program=<name> (program name or project pathname) to target one of the programs open in the tool; an unknown name is 404 PROGRAM_NOT_FOUND. New GET /programs/open-programs, POST /programs/open, POST /programs/switch, POST /programs/close; bridge tools programs_list_open/programs_open/programs_switch/programs_close and a program parameter on functions_list, functions_get, functions_decompile, scalars_search and the tools below; CLI ghydra programs list-open|open|switch|close.
  • Bookmarks: GET /bookmarks, POST /bookmarks, DELETE /bookmarks/{address}?type=; bridge bookmarks_list/bookmarks_add/bookmarks_delete.
  • Batch operations: POST /batch/rename-functions, /batch/set-comments, /batch/define-data apply many edits in one transaction with a per-item status; bridge batch_* tools.
  • Async decompilation: POST /functions/decompile-async returns a task id; poll GET /tasks/{id} and fetch GET /tasks/{id}/result; bridge functions_decompile_async, tasks_get_status, tasks_get_result.
  • Bridge data helpers: memory_search_bytes (over GET /memory/search), data_clear (with an optional byte size, via DELETE /data/{address}?size=N), data_create_label, data_at_address, datatypes_apply.
  • Decompiler constant inlining: the decompiler is pinned to respect read-only memory (Ghidra's default), so constants from read-only blocks are shown inline.

Changed

  • Loopback by default: the HTTP server binds to 127.0.0.1. Set -Dghidra.mcp.bind.host=0.0.0.0 (or GHYDRA_BIND_HOST) for cross-host setups such as a bridge in WSL.
  • Build requires GHIDRA_HOME: the bundled Ghidra JARs are removed, and the extension's version/ghidraVersion are read from $GHIDRA_HOME/Ghidra/application.properties, so every build matches the Ghidra it was compiled against.
  • Bridge discovery: instance discovery and health checks run in parallel; default-host scans are cached for 5 seconds.
  • POST /programs/close refuses a program with unsaved changes unless discard is true.

Fixed

  • MCP prompts: analyze_function, identify_vulnerabilities and reverse_engineer_binary return text built from Pydantic context models; FastMCP could not render the previous dict results.

GhydraMCP v2.3.0

Choose a tag to compare

@balcsida balcsida released this 18 Mar 07:56
f69cf2a

GhydraMCP v2.3.0

Major release with multi-file support, batch operations, and features ported from upstream GhidraMCP and starsong-consulting PRs.

Highlights

  • Multi-file support — Open, close, and switch between multiple programs in the same Ghidra instance. Pass ?program=name to any endpoint to target a specific open program without switching.
  • Batch operations — Rename multiple functions, set comments at many addresses, and define data items in bulk, all in single atomic transactions.
  • Scalar value search — Search for constant values in instructions with function context filtering.
  • Fully-qualified symbol names — All symbol lookups now use FQN for disambiguation. Renames support namespace changes via Namespace::name syntax.
  • Async decompilation — Start long-running decompilations in the background and poll for results via task IDs.
  • Byte pattern search — Search all program memory for hex byte patterns.
  • Bookmark management — Add, list, and delete Ghidra bookmarks via API.
  • Security — HTTP server now binds to 127.0.0.1 only.
  • Compatible with any Ghidra version — No version constraint in extension.properties.

New Endpoints & Tools

Feature Endpoints MCP Tools
Multi-file /programs/open-programs, /programs/open, /programs/close, /programs/switch programs_list_open, programs_open, programs_close, programs_switch
Batch ops /batch/rename-functions, /batch/set-comments, /batch/define-data batch_rename_functions, batch_set_comments, batch_define_data
Scalar search /scalars scalars_search
Async decompile /functions/decompile-async, /tasks/{id}, /tasks/{id}/result functions_decompile_async, tasks_get_status, tasks_get_result
Byte search /memory/search memory_search_bytes
Bookmarks /bookmarks bookmarks_list, bookmarks_add, bookmarks_delete
Data enhancements /data/clear, /data/label, /data/at/{addr} data_clear, data_create_label, data_at_address
Type application /datatypes/apply datatypes_apply

Improvements

  • All endpoints accept ?program=name query parameter for multi-file targeting
  • Fully-qualified symbol names (FQN) for function/data/symbol lookups and disambiguation
  • Namespace-aware renaming: functions_rename(new_name="MyClass::myMethod") creates namespaces automatically
  • Data list endpoint now properly supports name, name_contains, and type query filters
  • Struct, enum, and union creation supports inline field/value definitions
  • Decompiler inlines constant values from read-only memory (setRespectReadOnly)
  • MCP bridge type annotations improved, default timeout increased to 30s
  • Pydantic models for prompt context (fixes prompt serialization in FastMCP)
  • CLI: new ghydra programs command group for multi-file management

Breaking Changes

  • Bundled Ghidra JARs removed — Set GHIDRA_HOME environment variable to your Ghidra installation directory before building from source. Reduces repo size by ~33MB.
  • FQN symbol names — Function/symbol names are now returned as fully-qualified (e.g. MyClass::myMethod). Lookups accept both bare names and FQN.
  • API version bumped to 2030, plugin version to v2.3.0

Credits