CVE-2026-52750

Published Jun 10, 2026

Last updated 20 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-52750 describes a command injection vulnerability found in Ghidra versions prior to 12.1. This flaw specifically impacts the handling of URL annotations within the software when running on Windows operating systems. The vulnerability stems from the improper escaping of `cmd.exe` metacharacters. Attackers can exploit this by embedding malicious URLs within program comments. If a user operating Ghidra clicks on such a specially crafted URL, arbitrary commands can be executed under the privileges of the Ghidra user.

Description
Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims click.
Source
disclosure@vulncheck.com
NVD status
Analyzed
Products
ghidra

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

disclosure@vulncheck.com
CWE-88

Social media

Hype score
Not currently trending

Configurations