Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-11858


A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing​


Published

2024-12-15T14:15:22.320

Last Modified

2025-08-05T17:56:17.560

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application radare radare2 ≤ 5.9.8 Yes

References