CVE-2026-52750

HIGH

Ghidra < 12.1- Command Injection via URL Annotation Click

Title source: cna
STIX 2.1

Description

Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims click.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-5c38-3rf3-gp75)
https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-5c38-3rf3-gp75

Scores

CVSS v3 7.8
EPSS 0.0050
EPSS Percentile 38.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-88
Status published
Products (3)
nationalsecurityagency/ghidra < 12.1
nationalsecurityagency/ghidra 12.1
nsa/ghidra < 12.1
Published Jun 10, 2026
Tracked Since Jun 10, 2026