PT-2026-48411 · Ghidra · Ghidra

·

CVE-2026-52751

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghidra versions prior to 12.1
Description An unsafe deserialization issue exists in the client-side Shared-Project RMI connection code, enabling unauthenticated remote code execution. An attacker can create a malicious project file containing a ghidra:// URL. When this file is opened through the File → Open Project menu, the application deserializes untrusted objects using a Jython 2.7.4 gadget chain—a sequence of executable code fragments—to run arbitrary commands.
Recommendations Update to version 12.1.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52751
GHSA-FGG5-G275-7742

Affected Products

Ghidra