tag
Ghidra
CVE-2026-18718
misc
HIGH 7.5
Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)
Opening someone else's Ghidra project is enough to execute their code — with no prompt, no signature check, and no integrity verification.
Patched
2026-08-09
None assigned as of 2026-07-03
binary
MEDIUM
Ghidra 12.1.2 Conditional Swift Demangler ACE (plus TraceRMI RCE and SevenZipJBinding Reachability)
This entry packages three conditional, defensively-scoped findings against Ghidra 12.1.2 rather than a single unconditional exploit. First, the Swift demangler analyzer builds and launches a swift-demangle executable from a program/analyzer-controlled tool…
Unverified
2026-07-03