MEDIUM
radare2 < 6.1.4 Project Notes Path Traversal via Symlink
Published Apr 23, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.21%
Description
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory.
Affected products
-
- Version 0StatusaffectedConstraints<6.1.4
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25302 Advisory
- https://github.com/radareorg/radare2/commit/4bcdee725ff0754ed721a98789c0af371c5f32a4 patch
- https://github.com/radareorg/radare2/pull/25831 issue-trackingExploitIssue TrackingThird Party Advisory
- https://www.vulncheck.com/advisories/radare2-project-notes-path-traversal-via-symlink third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25302 | Advisory | |
| https://github.com/radareorg/radare2/commit/4bcdee725ff0754ed721a98789c0af371c5f32a4 | patch | |
| https://github.com/radareorg/radare2/pull/25831 | issue-trackingExploitIssue TrackingThird Party Advisory | |
| https://www.vulncheck.com/advisories/radare2-project-notes-path-traversal-via-symlink | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 23, 2026
Updated Jul 14, 2026
Reserved Apr 23, 2026
Link CVE-2026-6941
CISA Vulnrichment
Updated Apr 24, 2026
ENISA EUVD
EUVD-2026-25302 Assigner VulnCheck
Published Apr 23, 2026
Updated Jul 14, 2026
Exploited since n/a
Link EUVD-2026-25302