CVE-2026-52752: Ghidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry Names
Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitrary files outside the intended directory, enabling code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghidrato a version that resolves this vulnerability.Fixed in 12.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-52752?
CVE-2026-52752 has a high severity score of 8.4.
What software is affected by CVE-2026-52752?
CVE-2026-52752 affects Ghidra versions prior to 12.0.2.
How do I fix CVE-2026-52752?
To fix CVE-2026-52752, upgrade to Ghidra version 12.0.2 or later.
What type of vulnerability is CVE-2026-52752?
CVE-2026-52752 is classified as a path traversal vulnerability.
How can attackers exploit CVE-2026-52752?
Attackers can exploit CVE-2026-52752 by crafting malicious ZIP entries containing traversal sequences to write files outside the intended directory.