High severity7.8NVD Advisory· Published Jun 10, 2026· Updated Jun 11, 2026
CVE-2026-52752
CVE-2026-52752
Description
Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitrary files outside the intended directory, enabling code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*range: <12.0.2
- (no CPE)range: <12.0.2
Patches
Vulnerability mechanics
References
2- github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-jhc2-q7qf-9c25nvdExploitVendor Advisory
- www.vulncheck.com/advisories/ghidra-path-traversal-in-extension-installer-via-zip-entry-namesnvdThird Party Advisory
News mentions
1- National Security Agency's Ghidra: 15 Vulnerabilities Disclosed on June 10, 2026Vypr Intelligence · Jun 10, 2026