PT-2026-33002 · Radare2 · Radare2

Junrong

·

Published

2026-04-15

·

Updated

2026-04-15

·

CVE-2026-40499

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions radare2 versions prior to 6.1.4
Description A command injection issue exists in the PDB parser's print gvars() function. An attacker can execute arbitrary commands by embedding a newline byte in the PE section header name field. This is achieved by crafting a malicious PDB file with specific section names that inject r2 commands, which are then executed when the idp command processes the file.
Recommendations Update to version 6.1.4 or later. As a temporary workaround, avoid using the idp command to process untrusted PDB files.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40499
OPENSUSE-SU-2026:10555-1

Affected Products

Radare2