CVE-2026-52751: Nsa Ghidra

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File → Open Project, deserializes untrusted objects using a Jython 2.7.4 gadget chain to execute arbitrary commands.

Affected products

  • Nsa Ghidra: before 12.1 (fixed in 12.1)

Published 2026-06-10. Last modified 2026-07-14.