CVE-2024-11858: Radare RADARE2

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​

Affected products

  • Radare RADARE2: up to and including 5.9.8

Published 2024-12-15. Last modified 2026-06-17.