CVE-2024-11858

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
15/12/2024
Last modified:
05/08/2025

Description

A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* 5.9.8 (including)


References to Advisories, Solutions, and Tools