Ghostwire

CVE-2026-41015: radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP....

HIGH CVSS 7.5

Published: April 16, 2026 | Last Modified: April 16, 2026

Description

radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References