CVE-2026-18718: Uncontrolled Search Path Element in National Security Agency Ghidra
Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.
AI Analysis
Technical Summary
CVE-2026-18718 is an arbitrary code execution vulnerability in the National Security Agency's Ghidra software, specifically in the Swift demangler analyzer. The flaw arises because the SwiftNativeDemangler executes a binary resolved from a persisted Swift tool directory path stored in a Ghidra project without verifying its integrity or signature. By supplying a malicious project with a crafted Swift tool directory path, an attacker can cause Ghidra to run arbitrary executables under the user's context when the project is opened. This vulnerability requires local access to open the malicious project and user interaction to trigger execution.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Ghidra, potentially leading to full compromise of the user's environment. There is no indication of remote exploitation without user interaction. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid opening untrusted or suspicious Ghidra projects, especially those containing Swift tool directory paths. Monitor official NSA Ghidra advisories for updates and patches.
CVE-2026-18718: Uncontrolled Search Path Element in National Security Agency Ghidra
Description
Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra project with a crafted Swift tool directory path. When a victim opens the attacker-supplied project, SwiftDemanglerAnalyzer restores the persisted Swift binary directory from project state and SwiftNativeDemangler executes the resolved binary without integrity or signature verification, causing attacker-controlled executables to run under the Ghidra process user with no prompt or confirmation.
CVSS v4.0
Score 7.1high
Affected software
National Security Agency
Ghidra
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18718 is an arbitrary code execution vulnerability in the National Security Agency's Ghidra software, specifically in the Swift demangler analyzer. The flaw arises because the SwiftNativeDemangler executes a binary resolved from a persisted Swift tool directory path stored in a Ghidra project without verifying its integrity or signature. By supplying a malicious project with a crafted Swift tool directory path, an attacker can cause Ghidra to run arbitrary executables under the user's context when the project is opened. This vulnerability requires local access to open the malicious project and user interaction to trigger execution.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Ghidra, potentially leading to full compromise of the user's environment. There is no indication of remote exploitation without user interaction. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid opening untrusted or suspicious Ghidra projects, especially those containing Swift tool directory paths. Monitor official NSA Ghidra advisories for updates and patches.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-03T16:42:07.892Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a70cd6fbf32cb7a34ebce8b
Added to database: 08/03/2026, 17:18:39 UTC
Last enriched: 08/11/2026, 18:06:48 UTC
Last updated: 09/17/2026, 14:17:25 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.