CVE-2026-41015Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release), the date range for the vulnerable code was less than a week, occurring after 6.1.2 but before 6.1.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-16); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-16: 2Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-21: 104-1604-21
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-162
Disclosure2
2026-04-211
Patch1
Full discourse3 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🔥 Low‑level recon risk: CVE‑2026‑41015 in radare2. rabin2 (no‑SSL mode on UNIX) allows OS command injection via malicious PDB names. If you run untrusted binaries through older radare2 builds, treat this as active‑attack surface. Patch: use commit ≥ 9236f44 or the latest stable release. #CVE2026‑41015 #radare2 #commandinjection https://nvd.nist.gov/vuln/detail/CVE-2026-41015

    Post summary

    CVE‑2026‑41015 is an OS command injection vulnerability in radare2’s rabin2, mitigated by updating to the latest stable release or applying commit 9236f44. No PoC or active exploitation is reported.

    1001048
    1.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41015 Command Injection in radare2 via PDB Name to rabin2 -PP https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41015

    Post summary

    A new command injection vulnerability (CVE-2026-41015) affecting radare2 has been disclosed; details are listed on vulmon.com.

    0000065
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41015 radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the lates… https://www.cve.org/CVERecord?id=CVE-2026-41015

    Post summary

    The text announces a command‑injection vulnerability in radare2 (CVE-2026-41015) that occurs when using the rabin2 tool with a PDB name on UNIX systems without SSL.

    00000103
    57.2K followersView on X

Explore more