radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-78"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6942.json"
}{
"cpe": "cpe:2.3:a:radare:radare2_mcp_server:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.7.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6942.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "180708185000922059934304682165142928659",
"length": 1343
},
"id": "CVE-2026-6942-40a4e29d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2-mcp/commit/482cde6500009112a8bc0b3fa8d2ef6180581ec0",
"target": {
"file": "src/main.c",
"function": "r2mcp_help"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"140844049339296246461261873252428950825",
"215524335381702860358654473527460231839",
"33449073758504183663893682074283566598",
"35238454944620813338738681220355565984"
],
"threshold": 0.9
},
"id": "CVE-2026-6942-4932dec4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2-mcp/commit/482cde6500009112a8bc0b3fa8d2ef6180581ec0",
"target": {
"file": "src/r2mcp.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "260769827821383607432784434101256043269",
"length": 2251
},
"id": "CVE-2026-6942-755d5f4a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2-mcp/commit/482cde6500009112a8bc0b3fa8d2ef6180581ec0",
"target": {
"file": "src/r2api.inc.c",
"function": "r2_open_file"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "478327134458843260430798760578178914",
"length": 4375
},
"id": "CVE-2026-6942-aa80f2a8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2-mcp/commit/482cde6500009112a8bc0b3fa8d2ef6180581ec0",
"target": {
"file": "src/main.c",
"function": "r2mcp_main"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"4770524068687716923470429608539721772",
"7702088561517896587138730276773512342",
"284100001198787665481206861585648521711",
"104196166559340612694159104870872394868",
"316127583010610637406703448685694650936",
"240881696496639771453142091872124835062",
"32660916374798172436162306855780994733",
"41684883616168903381801276013555874718",
"334834244141277472643629708044323878252",
"81470357651492073925273027122545359910",
"122633016554927534310392592634266081269",
"152841947151492647392875455938553311536",
"220877191789714227173557630752513385673",
"86523813053075966446420484196373566517",
"313503715185718358535656766298123661008",
"152089167242220124951931289645503020263",
"145128796917078185586594538287760636646",
"99227860786558377835066484227210996296",
"193314868307455462667347452793874177039",
"154394836563429291462714620597711643547",
"191038878897604223421604393403890766466",
"25269904803311839235021005452429951467",
"7292787077607198149589120143470314188",
"66809940759812164272602762126009998876",
"146348421082690322454081157903160224165",
"319936116129729724981337501044535737584",
"7292787077607198149589120143470314188"
],
"threshold": 0.9
},
"id": "CVE-2026-6942-b3fe8693",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2-mcp/commit/482cde6500009112a8bc0b3fa8d2ef6180581ec0",
"target": {
"file": "src/main.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"101029790868538275367289906361682656511",
"185955304862066307554872794079786751701",
"120931816491304180565569266455536288770",
"264909951250632165860558862384663733967",
"294700051128761817583683378174948613880",
"204485373719952069875323464151501817793",
"210462367100063583412372041285303437269",
"46697268077320335480961848880931633329",
"134589438794459228264479084642453180848",
"259635885618288192658787842972410384857",
"129551061432245311828283595026447527699"
],
"threshold": 0.9
},
"id": "CVE-2026-6942-c6034786",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/radareorg/radare2-mcp/commit/482cde6500009112a8bc0b3fa8d2ef6180581ec0",
"target": {
"file": "src/r2api.inc.c"
}
}
]
"2026-08-12T16:10:01Z"