Executive brief
Ghidra, a popular software reverse-engineering suite, is vulnerable to a flaw that allows attackers to run malicious commands on a user's Windows computer. By tricking a user into clicking a specially crafted web link (URL) embedded in a program comment or project, an attacker can gain the same level of access as the user. This could lead to the theft of sensitive research data, malware samples, or unauthorized access to the analyst's workstation.
Technical details
Ghidra before version 12.1 is vulnerable to a command injection flaw on Windows due to improper neutralization of shell metacharacters in URL annotations. When a user clicks a {@url ...} annotation, Ghidra invokes 'cmd.exe /c start <URL>' via Runtime.getRuntime().exec(String[]). Because Java's Windows process implementation only escapes whitespace and double quotes, cmd.exe metacharacters like '&', '|', and '^' are passed unescaped. An attacker can craft a URL containing these characters (e.g., 'http://example.com?a=b&calc.exe') to break out of the intended command and execute arbitrary code. This is a variation of the 'BatBadBut' class of vulnerabilities. The issue is fixed in Ghidra 12.1.
Affected products
- NSA Ghidra < 12.1
Timeline
- 2026-05-14: advisory: GitHub Security Advisory published by NSA developers
- 2026-06-10: disclosed: CVE published and NVD record created