QSearchQSearch

CVE-2026-52750

7.8 HIGH

Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not ...

Published: 2026-06-10 · Last updated: 2026-06-10

Severity and scoring

CVSS
7.8 HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-88

Description

Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metacharacters are not properly escaped. Attackers can execute arbitrary commands under the Ghidra user's privileges by embedding malicious URLs in program comments that victims click.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-46529 Atril Document Viewer is the default document reader of the MATE desktop environment for Linux
  • CVE-2026-53694 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.T...
  • CVE-2026-11332 A flaw was found in ansible-core (7.8 HIGH)
  • CVE-2026-41013 Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to... (8.1 HIGH)
  • CVE-2026-49373 In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings (7.1 HIGH)