CVE-2026-41015: OS Command Injection
radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41015?
CVE-2026-41015 has not been assigned a severity score yet, but it allows command injection vulnerabilities in radare2.
How do I fix CVE-2026-41015?
To fix CVE-2026-41015, upgrade radare2 to version 6.1.3 or later.
What specific feature is vulnerable in CVE-2026-41015?
CVE-2026-41015 is vulnerable when using the rabin2 -PP command with a crafted PDB name.
Which versions of radare2 are affected by CVE-2026-41015?
Versions of radare2 from 6.1.2 up to but not including 6.1.3 are affected by CVE-2026-41015.
Can users mitigate CVE-2026-41015 without upgrading?
Users are recommended to use SSL configurations or avoid using rabin2 -PP with untrusted PDB names as a temporary mitigation for CVE-2026-41015.