NSA's Ghidra received multiple high-severity vulnerability disclosures affecting versions before 12.1 and, for one issue, before 12.0.2. The most critical findings include unauthenticated remote code execution in the Shared Project feature (CVE-2026-52751), where a malicious project file with a ghidra:// URL can trigger unsafe RMI deserialization before authentication when opened through File → Open Project. Advisories said the client uses ObjectInputStream.readObject() without a client-side ObjectInputFilter, and a working gadget chain exists using the bundled Jython 2.7.4 library. A separate Windows-specific flaw (CVE-2026-52750) allows command injection when a user clicks a malicious URL embedded in program comments because cmd.exe metacharacters are not properly escaped.
Additional disclosures affect other Ghidra components. CVE-2026-52758 is a SQL injection flaw in BSim search filters that lets a low-privileged remote attacker inject arbitrary SQL into PostgreSQL-backed queries and potentially read, modify, or delete database contents. CVE-2026-52752 is a path traversal bug in the extension installer that mishandles ZIP entry names such as ../, allowing files to be written outside the intended directory and potentially leading to code execution. The RMI deserialization issue reportedly affects standard Ghidra releases with Shared Project support since 9.1 across Linux, macOS, and Windows, and the disclosures point to fixes and mitigations in Ghidra 12.1 and related security advisories.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-10, CVE-2026-52754 was received by disclosure@vulncheck.com for an authentication bypass flaw in Ghidra before version 12.1. The issue in PKIAuthenticationModule.authenticate() allows a user with a valid CA-signed certificate to impersonate other users by supplying their public certificate with a null signature, enabling privilege escalation and repository compromise.
On 2026-06-10, CVE-2026-52758 was disclosed for Ghidra versions before 12.1, describing a SQL injection flaw in BSim filter handling. The advisory said a remote low-privileged attacker could inject arbitrary SQL through the BSim network query protocol and read, modify, or delete PostgreSQL data.
On 2026-06-10, a new vulnerability record for CVE-2026-52751 was added for Ghidra versions before 12.1, covering unsafe deserialization in the client-side Shared Project RMI connection code. The issue enables unauthenticated remote code execution when a user opens a malicious project file that triggers deserialization through a crafted ghidra:// URL.
On 2026-06-10, a path traversal vulnerability tracked as CVE-2026-52752 was disclosed for Ghidra versions before 12.0.2. The flaw stems from improper validation of ZIP entry names in the extension installer and can let a malicious extension write files outside the intended directory, potentially leading to code execution.
On 2026-06-10, CVE-2026-52750 was received by disclosure@vulncheck.com for a Windows command injection flaw in Ghidra's URL annotation handling. The issue affects versions before 12.1 and allows arbitrary command execution if a victim clicks a malicious link embedded in program comments.
On 2026-05-14, the National Security Agency's Ghidra project published a GitHub security advisory describing an unauthenticated remote code execution flaw in Ghidra's client-side Shared Project RMI handling. The advisory said the issue affected standard releases since version 9.1 and could be triggered by opening a malicious project file containing a ghidra:// URL.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcevulncheck.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.