CVE-2024-11858
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
15/12/2024
Last modified:
05/08/2025
Description
A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:* | 5.9.8 (including) |
To consult the complete list of CPE names with products and versions, see this page