Description
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

PeaZip versions earlier than 11.3.0 allow OS command injection when processing an archive that contains a filename with special quotation characters. The application fails to properly escape these characters, enabling an attacker to inject and execute arbitrary system commands during extraction. This flaw can compromise the integrity and confidentiality of the host system and is identified as CWE‑180.

Affected Systems

The vulnerability affects the PeaZip file archiver package before release 11.3.0. The affected builds are distributed through the official PeaZip releases and source tree, with cpe:2.3:a:peazip:peazip as the primary identifier. Users running any pre‑11.3.0 version should be aware that the application is susceptible to the flaw until a patch is applied.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity risk. EPSS data is unavailable, so the likelihood of exploitation remains uncertain, but the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by supplying a specially crafted archive file; if the application is run with sufficient privileges or in a shared environment, the injected commands could affect the entire system. The issue is mitigated by upgrading to the patched 11.3.0 release.

Generated by OpenCVE AI on October 2, 2026 at 23:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PeaZip to version 11.3.0 or newer.
  • Revert to the application's default configuration to avoid unnecessary use of filenames from archives.
  • Restrict archive extraction to trusted users and monitor for suspicious files.

Generated by OpenCVE AI on October 2, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:45:00 +0000

Type Values Removed Values Added
Title PeaZip Command Injection via Malformed Archive Filename

Fri, 02 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
Description PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
First Time appeared Peazip
Peazip peazip
Weaknesses CWE-180
CPEs cpe:2.3:a:peazip:peazip:*:*:*:*:*:*:*:*
Vendors & Products Peazip
Peazip peazip
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T22:37:54.551Z

Reserved: 2026-10-02T22:37:53.599Z

Link: CVE-2026-105050

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T23:16:58.093

Modified: 2026-10-02T23:16:58.093

Link: CVE-2026-105050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T23:30:10Z

Weaknesses
  • CWE-180

    Incorrect Behavior Order: Validate Before Canonicalize