CVE-2026-41015
published 2026-04-16CVE-2026-41015: radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use…
PriorityP345high7.4CVSS 3.1
AVLACHPRNUINSUCHIHAH
EPSS
1.16%
63.5th percentile
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| radare | radare2 | >= 01ca2f61fa43bd3f4b732447de31b16039d820c0 < 9236f44a28812fe911814e1b3a7bcf1e4de5d3c2 | 9236f44a28812fe911814e1b3a7bcf1e4de5d3c2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
radare2 6.1.2 on UNIX os command injection (Issue 25650)
vuldb·2026-04-16·CVSS 7.4
CVE-2026-41015 [HIGH] radare2 6.1.2 on UNIX os command injection (Issue 25650)
A vulnerability was found in radare2 6.1.2 on UNIX. It has been declared as critical. This affects an unknown function. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-41015. The attack can only be performed from a local environment. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-v352-gq4q-9qjf: radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP
ghsa_unreviewed·2026-04-16
CVE-2026-41015 [HIGH] CWE-78 GHSA-v352-gq4q-9qjf: radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.
No detection rules found.
No public exploits indexed.
https://github.com/radareorg/radare2/blob/9236f44a28812fe911814e1b3a7bcf1e4de5d3c2/SECURITY.md?plain=1#L3-L5https://github.com/radareorg/radare2/commit/9236f44a28812fe911814e1b3a7bcf1e4de5d3c2https://github.com/radareorg/radare2/issues/25650https://github.com/radareorg/radare2/pull/25651https://github.com/radareorg/radare2/issues/25650
2026-04-16
Published