๐Ÿ” CVE Alert

CVE-2026-18718

HIGH 7.0

Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State

CVSS Score
7.0
EPSS Score
0.0%
EPSS Percentile
0th

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.

CWE CWE-427
Vendor national security agency
Product ghidra
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for national security agency ghidra

Be the first to know when new high vulnerabilities affecting national security agency ghidra are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

National Security Agency / Ghidra
0 < 12.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-pcfh-853f-q3gh github.com: https://github.com/NationalSecurityAgency/ghidra/commit/c03a70d github.com: https://github.com/NationalSecurityAgency/ghidra app.notion.com: https://app.notion.com/p/Conditional-Arbitrary-Code-Execution-via-Swift-Demangler-Analyzer-ACE-GHIDRA-3a650723849f80679876df165fe4368b vulncheck.com: https://www.vulncheck.com/advisories/ghidra-swift-demangler-analyzer-arbitrary-code-execution-via-project-state

Credits

๐Ÿ” Sanket Sharma