{"id":"CVE-2026-6942","summary":"radare2-mcp \u003c=1.6.0 OS Command Injection via Shell Metacharacter Bypass","details":"radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication.","modified":"2026-07-16T03:31:13.595447941Z","published":"2026-04-23T20:58:10.022Z","database_specific":{"cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6942.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6942.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6942"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/radare2-mcp-os-command-injection-via-shell-metacharacter-bypass"},{"type":"REPORT","url":"https://github.com/radareorg/radare2-mcp/issues/45"},{"type":"FIX","url":"https://github.com/radareorg/radare2-mcp/commit/482cde6500009112a8bc0b3fa8d2ef6180581ec0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/radareorg/radare2-mcp","events":[{"introduced":"0"},{"fixed":"84bdd3afde7d11bcf7baddcd220e565c2e2c36f9"},{"fixed":"482cde6500009112a8bc0b3fa8d2ef6180581ec0"}],"database_specific":{"cpe":"cpe:2.3:a:radare:radare2_mcp_server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.7.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.6.0","1.5.6","1.5.4","1.5.2","1.5.0","1.4.2","1.4.0","1.3.0","1.2.0","1.1.0","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6942.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}