PT-2026-34752 · Radware+2 · Radare2

Published

2026-04-23

·

Updated

2026-04-24

·

CVE-2026-6941

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions radare2 versions prior to 6.1.4
Description An issue in project notes handling allows attackers to read or write files outside the configured project directory. This occurs when importing a malicious .zrp archive containing a symlinked notes.txt file, which bypasses directory confinement checks and allows operations to access arbitrary files outside the dir.projects root directory. Path traversal is a technique where attackers use special characters or symlinks to access files and directories that are stored outside the intended folder.
Recommendations Update to version 6.1.4 or later.

Exploit

Fix

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6941

Affected Products

Radare2