Command Injection Vulnerability in Ghidra by National Security Agency
CVE-2026-52750

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-52750?

A command injection vulnerability exists in Ghidra prior to version 12.1, specifically related to URL annotation handling on Windows. This issue arises due to improper escaping of cmd.exe metacharacters, which can allow attackers to inject arbitrary commands. When unsuspecting users click on malicious URLs embedded in program comments, it can lead to the execution of harmful commands under their privileges. This opens up a potential avenue for exploitation, necessitating users to upgrade to the latest version for protection.

Affected Version(s)

ghidra 0 < 12.1

ghidra 12.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ruffalo Lavoisier
.