GhydraMCP v2.3.0
GhydraMCP v2.3.0
Major release with multi-file support, batch operations, and features ported from upstream GhidraMCP and starsong-consulting PRs.
Highlights
- Multi-file support — Open, close, and switch between multiple programs in the same Ghidra instance. Pass
?program=nameto any endpoint to target a specific open program without switching. - Batch operations — Rename multiple functions, set comments at many addresses, and define data items in bulk, all in single atomic transactions.
- Scalar value search — Search for constant values in instructions with function context filtering.
- Fully-qualified symbol names — All symbol lookups now use FQN for disambiguation. Renames support namespace changes via
Namespace::namesyntax. - Async decompilation — Start long-running decompilations in the background and poll for results via task IDs.
- Byte pattern search — Search all program memory for hex byte patterns.
- Bookmark management — Add, list, and delete Ghidra bookmarks via API.
- Security — HTTP server now binds to
127.0.0.1only. - Compatible with any Ghidra version — No version constraint in extension.properties.
New Endpoints & Tools
| Feature | Endpoints | MCP Tools |
|---|---|---|
| Multi-file | /programs/open-programs, /programs/open, /programs/close, /programs/switch |
programs_list_open, programs_open, programs_close, programs_switch |
| Batch ops | /batch/rename-functions, /batch/set-comments, /batch/define-data |
batch_rename_functions, batch_set_comments, batch_define_data |
| Scalar search | /scalars |
scalars_search |
| Async decompile | /functions/decompile-async, /tasks/{id}, /tasks/{id}/result |
functions_decompile_async, tasks_get_status, tasks_get_result |
| Byte search | /memory/search |
memory_search_bytes |
| Bookmarks | /bookmarks |
bookmarks_list, bookmarks_add, bookmarks_delete |
| Data enhancements | /data/clear, /data/label, /data/at/{addr} |
data_clear, data_create_label, data_at_address |
| Type application | /datatypes/apply |
datatypes_apply |
Improvements
- All endpoints accept
?program=namequery parameter for multi-file targeting - Fully-qualified symbol names (FQN) for function/data/symbol lookups and disambiguation
- Namespace-aware renaming:
functions_rename(new_name="MyClass::myMethod")creates namespaces automatically - Data list endpoint now properly supports
name,name_contains, andtypequery filters - Struct, enum, and union creation supports inline field/value definitions
- Decompiler inlines constant values from read-only memory (
setRespectReadOnly) - MCP bridge type annotations improved, default timeout increased to 30s
- Pydantic models for prompt context (fixes prompt serialization in FastMCP)
- CLI: new
ghydra programscommand group for multi-file management
Breaking Changes
- Bundled Ghidra JARs removed — Set
GHIDRA_HOMEenvironment variable to your Ghidra installation directory before building from source. Reduces repo size by ~33MB. - FQN symbol names — Function/symbol names are now returned as fully-qualified (e.g.
MyClass::myMethod). Lookups accept both bare names and FQN. - API version bumped to 2030, plugin version to v2.3.0
Credits
- GhidraMCP by Laurie Wired — the original Ghidra MCP plugin
- Starsong Consulting — modular HATEOAS API architecture, CLI tool, MCP bridge rewrite, multi-instance support, and the overall GhydraMCP platform that this fork builds upon
- Incorporates ideas from upstream GhidraMCP PRs LaurieWired#43, LaurieWired#56, LaurieWired#57, LaurieWired#92, LaurieWired#110, LaurieWired#122, LaurieWired#124, LaurieWired#126, LaurieWired#132, LaurieWired#138, LaurieWired#139
- Ports features from starsong-consulting PRs starsong-consulting#15, starsong-consulting#17, starsong-consulting#18, starsong-consulting#20, starsong-consulting#22