<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CWE-427 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-427/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-427/index.xml" rel="self" type="application/rss+xml"/><item><title>Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)</title><link>https://poc.intelseclab.com/pocs/misc/2026-08-09_cve-2026-18718-ghidra-swift-demangler-code-execution/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-08-09_cve-2026-18718-ghidra-swift-demangler-code-execution/</guid><description>High severity (CVSS 7.5) — misc · CVE-2026-18718. Status: Patched. Affects: Ghidra (NSA reverse engineering framework), Swift Demangler analyzer. Tags: ghidra, nsa, reverse-engineering, swift, demangler, code-execution, project-file, analyzer, CWE-427, CWE-494, uncontrolled-search-path, supply-chain, research-tool, shared-project.</description><category>misc</category><category>High</category><category>ghidra</category><category>nsa</category><category>reverse-engineering</category><category>swift</category><category>demangler</category><category>code-execution</category><category>project-file</category><category>analyzer</category><category>CWE-427</category><category>CWE-494</category><category>uncontrolled-search-path</category><category>supply-chain</category><category>research-tool</category><category>shared-project</category></item><item><title>Discord Desktop Client Uncontrolled Search Path Element / Local Code Execution (CVE-2026-0776)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0776-discord-search-path/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0776-discord-search-path/</guid><description>High severity (CVSS 7.3) — binary · CVE-2026-0776 (ZDI-CAN-27057, credit: Trend Micro Zero Day Initiative). Status: PoC. Affects: Discord Desktop Client (Windows). Tags: discord, cwe-427, search-path-hijack, node-modules, local-code-execution, windows, electron.</description><category>binary</category><category>High</category><category>discord</category><category>cwe-427</category><category>search-path-hijack</category><category>node-modules</category><category>local-code-execution</category><category>windows</category><category>electron</category></item></channel></rss>