Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-03 17:16
Updated : 2026-08-04 20:16
NVD link : CVE-2026-18718
Mitre link : CVE-2026-18718
CVE.ORG link : CVE-2026-18718
JSON object : View
Products Affected
No product.
CWE
CWE-427
Uncontrolled Search Path Element
