CVE-2026-105050
HIGH
7,1
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: active
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because 'quotation character already used in the string' is mishandled.
180
Incorrect Behavior Order: Validate Before Canonicalize
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
https://app.secur0.com/certificate/ys3yqg-avrwaq-5ybnwl
https://github.com/peazip/PeaZip/commit/009fc35530e26729863969eddf4c18f1b48331cf
https://github.com/peazip/PeaZip/releases/tag/11.3.0
https://github.com/peazip/PeaZip/tree/sources/peazip-sources