CVE-2026-18718

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-03 17:16

Updated : 2026-08-04 20:16


NVD link : CVE-2026-18718

Mitre link : CVE-2026-18718

CVE.ORG link : CVE-2026-18718


JSON object : View

Products Affected

No product.

CWE
CWE-427

Uncontrolled Search Path Element