CVE-2026-18718
HIGHGhidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-18718. PoCs published by sn0x-sharma.
AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2026-18718, a conditional arbitrary code execution (ACE) vulnerability in Ghidra 12.1.2 via the Swift demangler analyzer. The PoC simulates the vulnerable execution path by launching a fake 'swift-demangle' binary and includes additional research components for TraceRMI and SevenZipJBinding surfaces.
Description
Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.
Exploits (1)
This repository provides a functional proof-of-concept for CVE-2026-18718, a conditional arbitrary code execution (ACE) vulnerability in Ghidra 12.1.2 via the Swift demangler analyzer. The PoC simulates the vulnerable execution path by launching a fake 'swift-demangle' binary and includes additional research components for TraceRMI and SevenZipJBinding surfaces.
References (7)
Scores
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H