radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malicious .zrp archive containing a symlinked notes.txt file. Attackers can craft a .zrp archive with a symlinked notes.txt that bypasses directory confinement checks, allowing note operations to follow the symlink and access arbitrary files outside the dir.projects root directory.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6941.json",
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-59"
]
}{
"cpe": "cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.1.4"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-22T03:57:29Z"
[
{
"digest": {
"function_hash": "271183476009708051612176031304899385513",
"length": 255.0
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2026-6941-d06b2d94",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2/commit/4bcdee725ff0754ed721a98789c0af371c5f32a4",
"target": {
"file": "libr/core/project.c",
"function": "r_core_project_notes_file"
}
},
{
"digest": {
"line_hashes": [
"10441492645088510910852734878490270980",
"227726708857502498108635116076088072477",
"210682476717650875576156456040481277937",
"173751060554162740724115094934246892340"
],
"threshold": 0.9
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2026-6941-da6bb9d2",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2/commit/4bcdee725ff0754ed721a98789c0af371c5f32a4",
"target": {
"file": "libr/core/project.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6941.json"