PT-2026-34753 · Radareorg · Radare2

Manthan Ghasadiya

·

Published

2026-04-23

·

Updated

2026-04-23

·

CVE-2026-6942

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2 cmd str(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6942

Affected Products

Radare2