PT-2026-34751 · Radware+2 · Radare2

Hinotoi-Agent

·

Published

2026-04-23

·

Updated

2026-04-24

·

CVE-2026-6940

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions radare2 versions prior to 6.1.4
Description A path traversal issue in project deletion allows local attackers to recursively delete arbitrary directories. By supplying absolute paths that escape the configured dir.projects root directory, attackers can target project marker files outside the project storage boundary. This action results in the recursive deletion of chosen directories using the permissions of the radare2 process, leading to loss of integrity and availability.
Recommendations Update to version 6.1.4 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6940

Affected Products

Radare2