AI description
CVE-2026-52750 describes a command injection vulnerability found in Ghidra versions prior to 12.1. This flaw specifically impacts the handling of URL annotations within the software when running on Windows operating systems. The vulnerability stems from the improper escaping of `cmd.exe` metacharacters. Attackers can exploit this by embedding malicious URLs within program comments. If a user operating Ghidra clicks on such a specially crafted URL, arbitrary commands can be executed under the privileges of the Ghidra user.
- Description
- Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims click.
- Source
- disclosure@vulncheck.com
- NVD status
- Analyzed
- Products
- ghidra
CVSS 4.0
- Type
- Secondary
- Base score
- 8.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- disclosure@vulncheck.com
- CWE-88
- Hype score
- Not currently trending
BrokenSec - Ghidra RCE Exploit kit Fully weaponized exploits for **CVE-2026-52751** and **CVE-2026-52750** Based on public research from bikini/exploitarium/ghidra-12.1.2-rce-ace-calc-poc #RCE #security #cybersec #hacking #0days #exploit #antisec #infosec #brokensec #security
@Johnsmithwjvmqq
1 Aug 2026
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️🚨⚠️🚨⚠️🚨⚠️ #BrokenSec - Ghidra RCE Exploit kit Fully weaponized exploits for **CVE-2026-52751** and **CVE-2026-52750** Based on public research from bikini/exploitarium/ghidra-12.1.2-rce-ace-calc-poc #RCE #security #cybersec #hacking #0days #exploit
@YogSoth0
31 Jul 2026
2615 Impressions
9 Retweets
47 Likes
21 Bookmarks
2 Replies
0 Quotes
CVE-2026-52750 - Command Injection in Ghidra on Windows. Malicious URLs in comments execute arbitrary commands. CVSS 7.8. Disable URL clicking or block untrusted files. #CVE #Ghidra #infosec A place for #cybersecurity experts mush bookmark https://t.co/rKtwelK63z
@HugoValters
11 Jun 2026
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*",
"matchCriteriaId": "84A6A7C7-BC80-477A-B69D-700BF1208830",
"versionEndExcluding": "12.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]