CVE-2026-52755: Nsa Ghidra

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filenames to execute arbitrary code or modify sensitive files like .bashrc or .ssh/authorized_keys.

Affected products

  • Nsa Ghidra: before 12.0.4 (fixed in 12.0.4)

Published 2026-06-10. Last modified 2026-07-14.