{"api_version":"1","generated_at":"2026-07-23T13:45:03+00:00","cve":"CVE-2020-15121","urls":{"html":"https://cve.report/CVE-2020-15121","api":"https://cve.report/api/cve/CVE-2020-15121.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-15121","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-15121"},"summary":{"title":"CVE-2020-15121","description":"In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2020-07-20 18:15:00","updated_at":"2023-11-07 03:17:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://github.com/radareorg/radare2/security/advisories/GHSA-r552-vp94-9358","name":"https://github.com/radareorg/radare2/security/advisories/GHSA-r552-vp94-9358","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Command injection during opening PE file with malformed debug symbol information (PDB) - `idpd` command · Advisory · radareorg/radare2 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/radareorg/radare2/issues/16945","name":"https://github.com/radareorg/radare2/issues/16945","refsource":"MISC","tags":["Third Party Advisory"],"title":"Command injection across r_sys_cmd* · Issue #16945 · radareorg/radare2 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","name":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Fix command injection on PDB download (#16966) · radareorg/radare2@04edfa8 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/radareorg/radare2/pull/16966","name":"https://github.com/radareorg/radare2/pull/16966","refsource":"MISC","tags":["Third Party Advisory"],"title":"Fix command injection on PDB download by GustavoLCR · Pull Request #16966 · radareorg/radare2 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWC7KNBETYE5MK6VIUU26LUIISIFGSBZ/","name":"FEDORA-2020-aa51efe207","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 32 Update: cutter-re-1.11.0-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MWC7KNBETYE5MK6VIUU26LUIISIFGSBZ/","name":"FEDORA-2020-aa51efe207","refsource":"","tags":[],"title":"[SECURITY] Fedora 32 Update: cutter-re-1.11.0-1.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YE77P5RSE2T7JHEKMWF2ARTSJGMPXCFY/","name":"FEDORA-2020-d5b33b6e6c","refsource":"","tags":[],"title":"[SECURITY] Fedora 31 Update: radare2-4.5.0-1.fc31 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YE77P5RSE2T7JHEKMWF2ARTSJGMPXCFY/","name":"FEDORA-2020-d5b33b6e6c","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 31 Update: radare2-4.5.0-1.fc31 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-15121","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15121","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"15121","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15121","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15121","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"radare","cpe5":"radare2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15121","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"radare","cpe5":"radare2","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-15121","qid":"501234","title":"Alpine Linux Security Update for radare2"},{"cve":"CVE-2020-15121","qid":"505368","title":"Alpine Linux Security Update for radare2"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2020-15121","STATE":"PUBLIC","TITLE":"Command injection in Radare2"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"radare2","version":{"version_data":[{"version_value":"< 4.5.0"}]}}]},"vendor_name":"radareorg"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}]}]},"references":{"reference_data":[{"name":"https://github.com/radareorg/radare2/security/advisories/GHSA-r552-vp94-9358","refsource":"CONFIRM","url":"https://github.com/radareorg/radare2/security/advisories/GHSA-r552-vp94-9358"},{"name":"https://github.com/radareorg/radare2/issues/16945","refsource":"MISC","url":"https://github.com/radareorg/radare2/issues/16945"},{"name":"https://github.com/radareorg/radare2/pull/16966","refsource":"MISC","url":"https://github.com/radareorg/radare2/pull/16966"},{"name":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9","refsource":"MISC","url":"https://github.com/radareorg/radare2/commit/04edfa82c1f3fa2bc3621ccdad2f93bdbf00e4f9"},{"refsource":"FEDORA","name":"FEDORA-2020-d5b33b6e6c","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YE77P5RSE2T7JHEKMWF2ARTSJGMPXCFY/"},{"refsource":"FEDORA","name":"FEDORA-2020-aa51efe207","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWC7KNBETYE5MK6VIUU26LUIISIFGSBZ/"}]},"source":{"advisory":"GHSA-r552-vp94-9358","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-07-20 18:15:00","lastModifiedDate":"2023-11-07 03:17:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"},"exploitabilityScore":2.8,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*","versionEndExcluding":"4.5.0","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"15121","Ordinal":"176500","Title":"CVE-2020-15121","CVE":"CVE-2020-15121","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"15121","Ordinal":"1","NoteData":"In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"15121","Ordinal":"2","NoteData":"2020-07-20","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"15121","Ordinal":"3","NoteData":"2020-08-06","Type":"Other","Title":"Modified"}]}}}