Description
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
Published: 2026-07-22
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An exploitation flaw exists in OhSoft CoffeeZip version 4.8.0.0 that permits an attacker to run arbitrary code by delivering a specially crafted archive file. Once the user downloads and extracts or executes the malicious archive, the application processes it in a way that allows the embedded code to be executed on the victim’s system, compromising confidentiality, integrity, and availability of the affected machine.

Affected Systems

The vulnerability is limited to OhSoft CoffeeZip ver. 4.8.0.0. No other product versions are listed as affected, and no vendor information is provided beyond the product name. Users operating this specific software version should be aware that the issue applies directly to them.

Risk and Exploitability

The flaw carries a high potential impact, as arbitrary code execution is a severe capability. The CVSS score is 8.8, indicating a high severity level, but the EPSS score of <1% suggests a low probability of exploitation at present. The attack vector is most likely local or requires user interaction, where an attacker supplies a malicious archive for the user to open or extract. Because the software automatically processes the archive contents, if an end user runs the file, the malicious code will execute, allowing the adversary to take complete control of the system. The vulnerability is not listed in the CISA KEV catalog at this time.

Generated by OpenCVE AI on August 4, 2026 at 00:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest OhSoft CoffeeZip release from the official vendor website to receive the fix for the CWE-693-related archive handling flaw.
  • Verify the integrity of the downloaded installer using the vendor’s cryptographic signature or hash before installation to prevent tampering and confirm the CWE-693 patch is applied.
  • If upgrading immediately is not possible, consider disabling automatic extraction and opening of archive files or configuring the application to require manual confirmation for executing content extracted from archives, thus limiting the exposed permissions highlighted by CWE-693.

Generated by OpenCVE AI on August 4, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Crafted Archive in OhSoft CoffeeZip 4.8.0.0

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Crafted Archive in OhSoft CoffeeZip 4.8.0.0

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Ohsoft
Ohsoft coffeezip
Vendors & Products Ohsoft
Ohsoft coffeezip

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
References

Subscriptions

Ohsoft Coffeezip
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-24T19:03:57.818Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-44090

cve-icon Vulnrichment

Updated: 2026-07-24T19:03:19.441Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:17:11.420

Modified: 2026-07-24T20:17:01.097

Link: CVE-2025-44090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:15:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure