CVE-2026-6941
published 2026-04-23CVE-2026-6941: radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the…
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.20%
9.7th percentile
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| radare | radare2 | < 6.1.4 | 6.1.4 |
| radareorg | radare2 | < 6.1.4 | 6.1.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2x93-pf6j-8c9x: radare2 prior to 6
ghsa_unreviewed·2026-04-23
CVE-2026-6941 [MEDIUM] CWE-59 GHSA-2x93-pf6j-8c9x: radare2 prior to 6
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory.
VulDB
radareorg radare2 up to 6.1.3 zrp Archive link following
vuldb·2026-04-23·CVSS 6.9
CVE-2026-6941 [MEDIUM] radareorg radare2 up to 6.1.3 zrp Archive link following
A vulnerability was found in radareorg radare2 up to 6.1.3. It has been classified as critical. Affected by this issue is some unknown functionality of the component zrp Archive Handler. Performing a manipulation results in link following.
This vulnerability is reported as CVE-2026-6941. The attack requires a local approach. No exploit exists.
It is suggested to install a patch to address this issue.
Citrix
Citrix Security Bulletin CTX139049
vendor_citrix·CVSS 5.0
CVE-2013-6938 [MEDIUM] Citrix Security Bulletin CTX139049
Citrix Security Bulletin CTX139049
CVE References: CVE-2013-6938, CVE-2013-6939, CVE-2013-6940, CVE-2013-6941, CVE-2013-6942, CVE-2013-6943, CVE-2013-6944, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6941 radare2: radare2: Arbitrary file read/write via path traversal in project notes handling [epel-all]
bugzilla·2026-04-25·CVSS 6.9
CVE-2026-6941 [MEDIUM] CVE-2026-6941 radare2: radare2: Arbitrary file read/write via path traversal in project notes handling [epel-all]
CVE-2026-6941 radare2: radare2: Arbitrary file read/write via path traversal in project notes handling [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6941 radare2: radare2: Arbitrary file read/write via path traversal in project notes handling [fedora-all]
bugzilla·2026-04-25·CVSS 6.9
CVE-2026-6941 [MEDIUM] CVE-2026-6941 radare2: radare2: Arbitrary file read/write via path traversal in project notes handling [fedora-all]
CVE-2026-6941 radare2: radare2: Arbitrary file read/write via path traversal in project notes handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6941 radare2: radare2: Arbitrary file read/write via path traversal in project notes handling
bugzilla·2026-04-23·CVSS 6.9
CVE-2026-6941 [MEDIUM] CVE-2026-6941 radare2: radare2: Arbitrary file read/write via path traversal in project notes handling
CVE-2026-6941 radare2: radare2: Arbitrary file read/write via path traversal in project notes handling
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory.
2026-04-23
Published