CVE-2026-6941(radare / radare2)
LOWCVSS 7.8 · HIGHImmediate actions
- Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory.
0.0/ 10 priority
Sources & remediation
Exploit / PoC references
Vendor / third-party advisories
Weakness type (CWE)
CWE-59CWE-22
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
NONE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- radare2
Affected systems
Vendors
Products
radare2
Deep dive
CPE platform detail1 entries
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | radare | radare2 | - | - | - |
