Remote Code Execution Vulnerability in Ghidra by National Security Agency
CVE-2026-52751
8.6HIGH
What is CVE-2026-52751?
A vulnerability in Ghidra software, prior to version 12.1, allows for unauthenticated remote code execution through an unsafe deserialization flaw in the client-side Shared-Project RMI connection. This flaw enables attackers to create malicious project files that, when opened, leverage a Jython 2.7.4 gadget chain to execute arbitrary commands. Due to improper handling of untrusted objects, users could unknowingly expose their systems to command execution risks.
Affected Version(s)
ghidra 0 < 12.1
ghidra 12.1
