216.73.216.133

CVE-2026-52750

· Published 10/06/2026 14:16 · Modified 11/06/2026 19:51

Labels: CVE-2026-52750 2026-06-10CVE-2026-52750CWE-88[email protected]

Essential information

Published
10/06/2026 14:16
Modified
11/06/2026 19:51
Author
Creator
CVSS
8.4 HIGH (v3) 8.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims click.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
nsa / ghidra cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*

References