« List of all CVEs

CVE-2026-6941

radare2 < 6.1.4 Project Notes Path Traversal via Symlink

Published: 4/23/2026 Last updated: 5/25/2026 Reserved: 4/23/2026

radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory.

CNA assigner: VulnCheck (83251b91-4cc7-4094-a5c7-464a1b83ea10) Requested by: n/a

Metrics

Version Score Severity Vector String
4.0 6.9 Medium CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
3.1 6.6 Medium CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L

Opam packages affected (2)

conf-radare2 radare2

Products affected (2)

Product Vendor Version
radare2 radareorg Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions
radare2 radareorg 2008 R2 for x64-based Systems Service Pack 1

References (6)

Credits (2)