CVE 8.4 HIGH

Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Import_CVE-2026-52755

8.4 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filenames to execute arbitrary code or modify sensitive files like .bashrc or .ssh/authorized_keys.

Basic Information

ID CVE-2026-52755
Source VulnCheck
Published Jun 10, 2026 at 12:41

Affected Product

Vendor nationalsecurityagency
Product ghidra
Affected Versions nationalsecurityagency ghidra 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.