GHSA-4pc8-6qgf-fgv2 · Severity: high — radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj...
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF parameter names that execute when radare2 analyzes the binary with aaa and subsequently runs afsvj, allowing arbitrary shell command execution through the unsanitized parameter interpolation in the pfq command string.
Conclusion & alert: CVE-2026-40527 is rated High Exploit Risk (69.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.92%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.07% | 0.92% | +0.84% |
| 2 | 2026-06-06 | 0.03% | 0.07% | +0.04% |
| 3 | 2026-04-18 | — | 0.03% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.5 | 4.0 | HIGH |
|
— | — | [email protected] |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
GHSA-4pc8-6qgf-fgv2 · Severity: high — radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-40527 not yet assigned priority: Debian including 1 source packages (radare2), 1 status rows across 1 suites (sid): resolved 1. | https://security-tracker.debian.org/tracker/CVE-2026-40527 |
ubuntu
|
medium | CVE-2026-40527 medium priority: Ubuntu including 1 source packages (radare2), 8 status rows across 8 suites (bionic, focal, jammy, noble, questing, resolute, upstream, xenial): needs-triage 7, DNE 1. | https://ubuntu.com/security/CVE-2026-40527 |
| URL | Tags |
|---|---|
| https://github.com/radareorg/radare2/commit/bc5a89033db3ecb5b1f7bf681fc6ba4dcfc14683 | Patch |
| https://github.com/radareorg/radare2/pull/25821 | Exploit Issue Tracking Patch |
| https://www.vulncheck.com/advisories/radare2-command-injection-via-dwarf-parameter-names | Third Party Advisory |