Deserialization of Untrusted Data in Ghidra - #VU131577
Published: May 15, 2026
Ghidra
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in Ghidra client-side Shared-Project connection code when opening a crafted project file that triggers a ghidra:// connection and deserializing RMI responses. A remote attacker can provide a specially crafted Ghidra project file to execute arbitrary code.
User interaction is required to open the project file.