CVE-2026-6940
published 2026-04-23CVE-2026-6940: radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by…
PriorityP434high7.1CVSS 3.1
AVLACLPRNUIRSUCNIHAH
EPSS
0.22%
12.3th percentile
radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to project marker files outside the project storage boundary to cause recursive deletion of attacker-chosen directories with permissions of the radare2 process, resulting in integrity and availability loss.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| radare | radare2 | < 6.1.4 | 6.1.4 |
| radareorg | radare2 | < 6.1.4 | 6.1.4 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x2x5-gj4j-p6qw: radare2 prior to 6
ghsa_unreviewed·2026-04-23
CVE-2026-6940 [MEDIUM] CWE-22 GHSA-x2x5-gj4j-p6qw: radare2 prior to 6
radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to project marker files outside the project storage boundary to cause recursive deletion of attacker-chosen directories with permissions of the radare2 process, resulting in integrity and availability loss.
VulDB
radareorg radare2 up to 6.1.3 path traversal
vuldb·2026-04-23·CVSS 6.9
CVE-2026-6940 [MEDIUM] radareorg radare2 up to 6.1.3 path traversal
A vulnerability described as critical has been identified in radareorg radare2 up to 6.1.3. This affects an unknown function. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-6940. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is recommended.
Citrix
Citrix Security Bulletin CTX139049
vendor_citrix·CVSS 5.0
CVE-2013-6938 [MEDIUM] Citrix Security Bulletin CTX139049
Citrix Security Bulletin CTX139049
CVE References: CVE-2013-6938, CVE-2013-6939, CVE-2013-6940, CVE-2013-6941, CVE-2013-6942, CVE-2013-6943, CVE-2013-6944, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6940 radare2: radare2: Recursive directory deletion via path traversal during project deletion [epel-all]
bugzilla·2026-04-25·CVSS 6.9
CVE-2026-6940 [MEDIUM] CVE-2026-6940 radare2: radare2: Recursive directory deletion via path traversal during project deletion [epel-all]
CVE-2026-6940 radare2: radare2: Recursive directory deletion via path traversal during project deletion [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6940 radare2: radare2: Recursive directory deletion via path traversal during project deletion [fedora-all]
bugzilla·2026-04-25·CVSS 6.9
CVE-2026-6940 [MEDIUM] CVE-2026-6940 radare2: radare2: Recursive directory deletion via path traversal during project deletion [fedora-all]
CVE-2026-6940 radare2: radare2: Recursive directory deletion via path traversal during project deletion [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6940 radare2: radare2: Recursive directory deletion via path traversal during project deletion
bugzilla·2026-04-23·CVSS 6.9
CVE-2026-6940 [MEDIUM] CVE-2026-6940 radare2: radare2: Recursive directory deletion via path traversal during project deletion
CVE-2026-6940 radare2: radare2: Recursive directory deletion via path traversal during project deletion
radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to project marker files outside the project storage boundary to cause recursive deletion of attacker-chosen directories with permissions of the radare2 process, resulting in integrity and availability loss.
2026-04-23
Published