PT-2026-33515 · Radare2 · Radare2

·

CVE-2026-40527

·

Published

2026-04-17

·

Updated

2026-04-20

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions radare2 versions prior to commit bc5a890
Description An issue exists in the 'afsv/afsvj' command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW TAG formal parameter names. When the software analyzes a binary using the aaa command and subsequently runs afsvj, unsanitized parameter interpolation in the pfq command string allows for arbitrary shell command execution.
Recommendations Update to the version containing commit bc5a890.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40527

Affected Products

Radare2