CVE-2026-40527Disclosure(radare / radare2)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF parameter names that execute when radare2 analyzes the binary with aaa and subsequently runs afsvj, allowing arbitrary shell command execution through the unsanitized parameter interpolation in the pfq command string.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • radare2

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
radare2

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-20: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 104-1704-1804-20
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-171
Disclosure1
2026-04-181
Disclosure1
2026-04-201
General1
Full discourse3 posts
  • Shota Zaizen (財前 匠汰)@z41zen
    General

    Built a security scanner. Trained it on 1,000 real-world CVE samples. It just detected CVE-2026-40527 a vulnerability I found in radare2. https://t.co/r71LcFcnu2

    Post summary

    The user reports that their scanner detected CVE‑2026‑40527 in radare2, but provides no further technical or exploit details.

    00010132
    38 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40527 radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command se… https://www.cve.org/CVERecord?id=CVE-2026-40527

    Post summary

    The text announces a command injection vulnerability (CVE‑2026‑40527) in radare2’s afsv/afsvj command path, allowing malicious ELF binaries to embed r2 commands, with a link to the CVE record.

    00000186
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40527 Command Injection in radare2 via Malicious DWARF Parameter Names https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40527

    Post summary

    A command‑injection vulnerability (CVE‑2026‑40527) in radare2, triggered by malicious DWARF parameter names, is disclosed, but no PoC, exploit, active exploitation, or patch information is provided.

    0000074
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appradareradare2---

Explore more