CVE 8.6 HIGH

Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection_CVE-2026-52751

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File → Open Project, deserializes untrusted objects using a Jython 2.7.4 gadget chain to execute arbitrary commands.

AI Analysis

Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection

Basic Information

ID CVE-2026-52751
Source VulnCheck
Published Jun 10, 2026 at 12:39

Affected Product

Vendor nationalsecurityagency
Product ghidra
Affected Versions nationalsecurityagency ghidra 0

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor National Security Agency
Product Ghidra
Version < 12.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.