CVE-2026-18718

HIGH

Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-18718. PoCs published by sn0x-sharma.

AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2026-18718, a conditional arbitrary code execution (ACE) vulnerability in Ghidra 12.1.2 via the Swift demangler analyzer. The PoC simulates the vulnerable execution path by launching a fake 'swift-demangle' binary and includes additional research components for TraceRMI and SevenZipJBinding surfaces.

Description

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.

Exploits (1)

github WORKING POC 1 stars
by sn0x-sharma · pythonpoc
https://github.com/sn0x-sharma/CVE-2026-18718

This repository provides a functional proof-of-concept for CVE-2026-18718, a conditional arbitrary code execution (ACE) vulnerability in Ghidra 12.1.2 via the Swift demangler analyzer. The PoC simulates the vulnerable execution path by launching a fake 'swift-demangle' binary and includes additional research components for TraceRMI and SevenZipJBinding surfaces.

Classification
Working Poc 99%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Ghidra 12.1.2
No auth needed
Prerequisites: Attacker-controlled Swift tool directory path configured in Ghidra · User interaction to trigger demangler analysis
mistral-large-3 · analyzed Aug 04, 2026 Full analysis →

Scores

CVSS v3 7.0
EPSS 0.0021
EPSS Percentile 10.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (2)
National Security Agency/Ghidra < 12.1.2
National Security Agency/Ghidra 12.1.3
Published Aug 03, 2026
Tracked Since Aug 03, 2026