๐Ÿ” CVE Alert

CVE-2026-41015

HIGH 7.4
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
1th

radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.

CWE CWE-78
Vendor radare
Product radare2
Published Apr 16, 2026
Last Updated Apr 16, 2026
Stay Ahead of the Next One

Get instant alerts for radare radare2

Be the first to know when new high vulnerabilities affecting radare radare2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

radare / radare2
01ca2f61fa43bd3f4b732447de31b16039d820c0 < 9236f44a28812fe911814e1b3a7bcf1e4de5d3c2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/radareorg/radare2/issues/25650 github.com: https://github.com/radareorg/radare2/pull/25651 github.com: https://github.com/radareorg/radare2/blob/9236f44a28812fe911814e1b3a7bcf1e4de5d3c2/SECURITY.md?plain=1#L3-L5 github.com: https://github.com/radareorg/radare2/commit/9236f44a28812fe911814e1b3a7bcf1e4de5d3c2