CVE-2026-52750: Ghidra < 12.1- Command Injection via URL Annotation Click
Published Jun 10, 2026
·Updated
Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims click.
Affected Software
2 affected components
National Security Agency Ghidra<12.1
NSA Ghidra<12.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghidrato a version that resolves this vulnerability.Fixed in 12.1
Event History
Jun 10, 2026
CVE Published
via MITRE·12:39 PM
Data Sourced
via MITRE·12:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-52750?
The severity of CVE-2026-52750 is high, with a score of 8.4.
2
How do I fix CVE-2026-52750?
To fix CVE-2026-52750, upgrade Ghidra to version 12.1 or later.
3
What type of vulnerability is described in CVE-2026-52750?
CVE-2026-52750 is a command injection vulnerability.
4
What platforms are affected by CVE-2026-52750?
CVE-2026-52750 affects Ghidra running on Windows.
5
What can attackers achieve by exploiting CVE-2026-52750?
Attackers can execute arbitrary commands under the Ghidra user's privileges.