Command injection in Ghidra - #VU131573
Published: May 15, 2026
Ghidra
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to command injection in the browser-launch configuration and URL annotation click handling on Windows when processing a clicked {@url ...} annotation embedded in program comments. A remote attacker can craft a malicious project, program, or script containing a URL annotation with cmd metacharacters to execute arbitrary code.
User interaction is required, and the issue affects Windows systems using the default browser-launch configuration.