Skip to content

Release v3.1.0

Latest

Choose a tag to compare

@github-actions github-actions released this 27 Sep 20:14
54a8c30

Fork (balcsida/GhydraMCP) changes on top of upstream 3.0.0-rc.1, ported onto the Javalin server.

Added

  • Multi-file support: every program-scoped endpoint accepts ?program=<name> (program name or project pathname) to target one of the programs open in the tool; an unknown name is 404 PROGRAM_NOT_FOUND. New GET /programs/open-programs, POST /programs/open, POST /programs/switch, POST /programs/close; bridge tools programs_list_open/programs_open/programs_switch/programs_close and a program parameter on functions_list, functions_get, functions_decompile, scalars_search and the tools below; CLI ghydra programs list-open|open|switch|close.
  • Bookmarks: GET /bookmarks, POST /bookmarks, DELETE /bookmarks/{address}?type=; bridge bookmarks_list/bookmarks_add/bookmarks_delete.
  • Batch operations: POST /batch/rename-functions, /batch/set-comments, /batch/define-data apply many edits in one transaction with a per-item status; bridge batch_* tools.
  • Async decompilation: POST /functions/decompile-async returns a task id; poll GET /tasks/{id} and fetch GET /tasks/{id}/result; bridge functions_decompile_async, tasks_get_status, tasks_get_result.
  • Bridge data helpers: memory_search_bytes (over GET /memory/search), data_clear (with an optional byte size, via DELETE /data/{address}?size=N), data_create_label, data_at_address, datatypes_apply.
  • Decompiler constant inlining: the decompiler is pinned to respect read-only memory (Ghidra's default), so constants from read-only blocks are shown inline.

Changed

  • Loopback by default: the HTTP server binds to 127.0.0.1. Set -Dghidra.mcp.bind.host=0.0.0.0 (or GHYDRA_BIND_HOST) for cross-host setups such as a bridge in WSL.
  • Build requires GHIDRA_HOME: the bundled Ghidra JARs are removed, and the extension's version/ghidraVersion are read from $GHIDRA_HOME/Ghidra/application.properties, so every build matches the Ghidra it was compiled against.
  • Bridge discovery: instance discovery and health checks run in parallel; default-host scans are cached for 5 seconds.
  • POST /programs/close refuses a program with unsaved changes unless discard is true.

Fixed

  • MCP prompts: analyze_function, identify_vulnerabilities and reverse_engineer_binary return text built from Pydantic context models; FastMCP could not render the previous dict results.