CVE-2026-6942: radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypass
radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2cmdstr(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
radare2-mcpto a version that resolves this vulnerability.Fixed in 1.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6942?
CVE-2026-6942 is classified as a critical severity vulnerability due to its ability to allow remote execution of arbitrary commands.
How do I fix CVE-2026-6942?
To mitigate CVE-2026-6942, upgrade radare2-mcp to version 1.6.1 or later where the vulnerability has been addressed.
Who is affected by CVE-2026-6942?
CVE-2026-6942 affects users of radare2-mcp version 1.6.0 and earlier.
What type of vulnerability is CVE-2026-6942?
CVE-2026-6942 is an OS command injection vulnerability that allows attackers to execute arbitrary commands.
Can CVE-2026-6942 be exploited remotely?
Yes, CVE-2026-6942 can be exploited remotely by attackers to run commands on the vulnerable system.