
CVE-2026-40499 radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary comman… https://www.cve.org/CVERecord?id=CVE-2026-40499
Post summary
The post announces a command injection vulnerability in radare2's PDB parser affecting versions prior to 6.1.4, without indicating exploitation, patches, or proof‑of‑concept details.
