Junglewise Threat Intelligence

CVE-2026-52750: NSA Ghidra command injection in URL annotation handling on Windows

CVE-2026-52750 · Severity: high · CVSS 7.8 · Published 2026-06-10

Technologies: National Security Agency Ghidra. Vendors: National Security Agency.

Executive brief

Ghidra, a popular software reverse-engineering suite, is vulnerable to a flaw that allows attackers to run malicious commands on a user's Windows computer. By tricking a user into clicking a specially crafted web link (URL) embedded in a program comment or project, an attacker can gain the same level of access as the user. This could lead to the theft of sensitive research data, malware samples, or unauthorized access to the analyst's workstation.

Technical details

Ghidra before version 12.1 is vulnerable to a command injection flaw on Windows due to improper neutralization of shell metacharacters in URL annotations. When a user clicks a {@url ...} annotation, Ghidra invokes 'cmd.exe /c start <URL>' via Runtime.getRuntime().exec(String[]). Because Java's Windows process implementation only escapes whitespace and double quotes, cmd.exe metacharacters like '&', '|', and '^' are passed unescaped. An attacker can craft a URL containing these characters (e.g., 'http://example.com?a=b&calc.exe') to break out of the intended command and execute arbitrary code. This is a variation of the 'BatBadBut' class of vulnerabilities. The issue is fixed in Ghidra 12.1.

Affected products

  • NSA Ghidra < 12.1

Timeline

  • 2026-05-14: advisory: GitHub Security Advisory published by NSA developers
  • 2026-06-10: disclosed: CVE published and NVD record created

References

Related threats