Impact
PeaZip versions earlier than 11.3.0 allow OS command injection when processing an archive that contains a filename with special quotation characters. The application fails to properly escape these characters, enabling an attacker to inject and execute arbitrary system commands during extraction. This flaw can compromise the integrity and confidentiality of the host system and is identified as CWE‑180.
Affected Systems
The vulnerability affects the PeaZip file archiver package before release 11.3.0. The affected builds are distributed through the official PeaZip releases and source tree, with cpe:2.3:a:peazip:peazip as the primary identifier. Users running any pre‑11.3.0 version should be aware that the application is susceptible to the flaw until a patch is applied.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity risk. EPSS data is unavailable, so the likelihood of exploitation remains uncertain, but the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by supplying a specially crafted archive file; if the application is run with sufficient privileges or in a shared environment, the injected commands could affect the entire system. The issue is mitigated by upgrading to the patched 11.3.0 release.
OpenCVE Enrichment