CVE-2026-6942Patch(radare / radare2_mcp_server)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch radare radare2_mcp_server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • radare2_mcp_server

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-26); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
radare2_mcp_server

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-23: 1Mentions · 2026-04-26: 2Mentions · 2026-07-16: 1PoC Mentioned / Linked · 2026-04-26: 1Exploit Tool / Code · 2026-04-26: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-26: 1Technical Details · 2026-07-16: 104-2304-2607-16
Signal classification4 categories
Patch
125.0%
Disclosure
125.0%
PoC
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-231
Patch1
2026-04-262
Disclosure1PoC1
2026-07-161
General1
Full discourse4 posts
  • Manthan Ghasadiya@g_m_j_2703
    General

    My findings: CVE-2026-6942 (radare2-mcp, CVSS 9.8), CVE-2026-42449 (n8n-mcp, CVSS 8.5), CVE-2026-35394 (mobile-mcp, CVSS 8.3). Plus issues in GitHub MCP, Kubernetes MCP, IDA Pro MCP, Chromium DevTools MCP, and AWS Diagram MCP.

    Post summary

    The post enumerates several high‑CVSS CVEs across various MCP tools but does not provide evidence of exploitation, PoC, or remediation.

    20030222
    131 followersView on X
  • Manthan Ghasadiya@g_m_j_2703
    PoC

    Full writeup + PoC: http://github.com/manthanghasadiya/writeups/tree/main/CVE-2026-6942 Found with mcpsec, my open-source MCP security scanner: http://github.com/manthanghasadiya/mcpsec CVE record: http://cve.org/CVERecord?id=CVE-2026-6942

    Post summary

    The text announces a writeup and PoC for CVE‑2026‑6942, providing a link to functional exploit code, but does not mention active exploitation, patches, or technical details.

    00011137
    125 followersView on X
  • Manthan Ghasadiya@g_m_j_2703
    Disclosure

    Security researchers: "Let me have my AI analyze this suspicious binary." The binary: *contains r2.cmd("!id")* Your terminal: uid=1000(researcher) gid=1000(researcher) CVE-2026-6942. CVSS 9.8. Full writeup below 🧵 https://t.co/OmTRV0gm8G

    Post summary

    Researchers posted a binary illustrating CVE-2026-6942, noting a CVSS score of 9.8, but no exploit code, patch info, or claims of active exploitation are provided.

    10010162
    125 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6942 — CVSS 9.8/10 ██████████ radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/FKFEUB21pp

    Post summary

    CVE-2026-6942 is a critical OS command injection flaw in radare2-mcp 1.6.0 and earlier; a patch is available.

    1000060
    28 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appradareradare2_mcp_server---

Explore more