CVE-2026-18718

Source
https://cve.org/CVERecord?id=CVE-2026-18718
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18718.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18718
Aliases
  • GHSA-pcfh-853f-q3gh
Published
2026-08-03T16:54:17.653Z
Modified
2026-08-04T11:31:17.020790863Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
Details

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.

Database specific
{
    "cwe_ids": [
        "CWE-427"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18718.json"
}
References

Affected packages

Git / github.com/nationalsecurityagency/ghidra

Affected ranges

Type
GIT
Repo
https://github.com/nationalsecurityagency/ghidra
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "12.1.2"
        }
    ]
}

Affected versions

Ghidra_10.*
Ghidra_10.3_build
Ghidra_12.*
Ghidra_12.1.1_build
Ghidra_12.1_build
Ghidra_9.*
Ghidra_9.0.1_build

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18718.json"