CVE-2026-18718: Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18718?
The severity of CVE-2026-18718 is rated as high, with a score of 7.
How do I fix CVE-2026-18718?
To fix CVE-2026-18718, update to the latest version of Ghidra where the vulnerability has been addressed.
What impact does CVE-2026-18718 have on users?
CVE-2026-18718 allows an attacker to execute arbitrary code through a malicious Ghidra project, posing a significant risk to users.
Who is affected by CVE-2026-18718?
Users of Ghidra who open projects from untrusted sources are affected by CVE-2026-18718.
What type of vulnerability is CVE-2026-18718?
CVE-2026-18718 is an arbitrary code execution vulnerability found in the Swift demangler analyzer of Ghidra.