PT-2026-34751 · Radware+2 · Radare2
Hinotoi-Agent
·
Published
2026-04-23
·
Updated
2026-04-24
·
CVE-2026-6940
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
radare2 versions prior to 6.1.4
Description
A path traversal issue in project deletion allows local attackers to recursively delete arbitrary directories. By supplying absolute paths that escape the configured
dir.projects root directory, attackers can target project marker files outside the project storage boundary. This action results in the recursive deletion of chosen directories using the permissions of the radare2 process, leading to loss of integrity and availability.Recommendations
Update to version 6.1.4 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Radare2