{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/national-security-agency/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7,"id":"CVE-2026-18718"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ghidra"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["National Security Agency"],"content_html":"\u003cp\u003eCVE-2026-18718 describes a critical arbitrary code execution vulnerability in the Swift demangler analyzer within the Ghidra reverse engineering framework. The vulnerability exists because the SwiftNativeDemangler component improperly handles path resolution for the Swift tool directory. When a user opens a project file, the SwiftDemanglerAnalyzer restores a persisted Swift binary directory path from the project state. Subsequently, the application executes a binary from the specified path without performing any integrity or signature validation. An attacker can craft a malicious Ghidra project file containing a path to a malicious executable. Upon opening the file, the executable runs under the context of the current Ghidra process user. This issue poses a significant risk to reverse engineering teams who frequently share and import third-party projects from untrusted sources, as the execution occurs without any warning or prompt to the user.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows local arbitrary code execution under the privileges of the user running Ghidra. This could lead to full system compromise, exfiltration of sensitive reverse engineering data, or lateral movement within a developer's workstation environment. The scope of impact is limited to users who open malicious project files, but given the collaborative nature of security research, the distribution of compromised project files represents a high-risk vector for the research community.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdvise all users to avoid opening Ghidra projects received from untrusted or unverified third-party sources.\u003c/li\u003e\n\u003cli\u003eImplement workstation-level restrictions to prevent Ghidra from executing binaries from temporary directories or user-writable locations.\u003c/li\u003e\n\u003cli\u003eReview the official National Security Agency Ghidra security advisories for the release of a patched version.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual child processes spawned by the Ghidra process (ghidraRun or related binaries) using endpoint detection tools.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T18:06:17Z","date_published":"2026-08-03T18:06:17Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ghidra-rce/","summary":"An arbitrary code execution vulnerability in the Ghidra Swift demangler analyzer allows attackers to execute arbitrary binaries by manipulating the Swift tool directory path within a project file.","title":"Arbitrary Code Execution in Ghidra Swift Demangler","url":"https://feed.craftedsignal.io/briefs/2026-08-ghidra-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - National Security Agency","version":"https://jsonfeed.org/version/1.1"}