The vulnerability in Radare2 affects versions up to and including 5.9.8. When processing malicious Pebble Application files, Radare2 improperly sanitizes user-controlled input, leading to command injection. This allows arbitrary shell commands to execute during file handling. The issue was confirmed in version 5.9.7 on Linux x86-64 and demonstrated with a Base64-encoded test file