Vulnerability Description
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/radareorg/radare2/blob/9236f44a28812fe911814e1b3a7bcf1e4de5d3
- https://github.com/radareorg/radare2/commit/9236f44a28812fe911814e1b3a7bcf1e4de5
- https://github.com/radareorg/radare2/issues/25650
- https://github.com/radareorg/radare2/pull/25651
- https://github.com/radareorg/radare2/issues/25650
FAQ
What is CVE-2026-41015?
CVE-2026-41015 is a vulnerability with a CVSS score of 7.4 (HIGH). radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release)...
How severe is CVE-2026-41015?
CVE-2026-41015 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41015?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.