CVE Feed

    Dashboard / CVE / CVE-2026-18718

    CVE-2026-18718

    Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.

    Published:Aug 3, 2026
    Last Modified:Aug 14, 2026
    EPS:Aug 3, 2026
    EPSS Score:0.00206
    CVSS Score:7

    Affected Products

    Vendor
    Nationalsecurityagency
    Product
    Ghidra
    Vendor
    Nsa
    Product
    Ghidra

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High