CVE-2026-52755

HIGH

Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Import

Title source: cna
STIX 2.1

Description

Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filenames to execute arbitrary code or modify sensitive files like .bashrc or .ssh/authorized_keys.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-3r55-xjr4-jh8f)
https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-3r55-xjr4-jh8f

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 5.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (3)
nationalsecurityagency/ghidra < 12.0.4
nationalsecurityagency/ghidra 12.0.4
nsa/ghidra < 12.0.4
Published Jun 10, 2026
Tracked Since Jun 10, 2026