radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 16 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3. | |
| First Time appeared |
Radare
Radare radare2 |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Radare
Radare radare2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-16T02:44:57.723Z
Reserved: 2026-04-16T02:35:46.790Z
Link: CVE-2026-41015
No data.
Status : Received
Published: 2026-04-16T03:16:27.440
Modified: 2026-04-16T03:16:27.440
Link: CVE-2026-41015
No data.
OpenCVE Enrichment
Updated: 2026-04-16T03:30:05Z
Weaknesses