Path Traversal Vulnerability in Ghidra by National Security Agency
CVE-2026-52752
8.4HIGH
What is CVE-2026-52752?
Ghidra versions prior to 12.0.2 are vulnerable to a path traversal issue in the extension installer. This vulnerability allows attackers to create malicious extensions that exploit improper validation of ZIP entry names during file extraction. By including traversal sequences like ../ in the filenames, attackers can write arbitrary files outside of the expected directory, potentially leading to code execution on the host system.
Affected Version(s)
ghidra 0 < 12.0.2
ghidra 12.0.2
