CVE-2026-105050

Published: Ott 03, 2026 Last Modified: Ott 03, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,1
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: active
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because 'quotation character already used in the string' is mishandled.

180

Incorrect Behavior Order: Validate Before Canonicalize

Draft
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
View CWE Details
https://app.secur0.com/certificate/ys3yqg-avrwaq-5ybnwl
https://github.com/peazip/PeaZip/commit/009fc35530e26729863969eddf4c18f1b48331cf
https://github.com/peazip/PeaZip/releases/tag/11.3.0
https://github.com/peazip/PeaZip/tree/sources/peazip-sources