CVE-2026-105050
Received Received - Intake

PeaZip OS Command Injection via Archive Filename

Vulnerability report for CVE-2026-105050, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
peazip peazip to 11.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-180 The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PeaZip before version 11.3.0 has a vulnerability where, in a non-default configuration, a filename in an archive can be manipulated to inject OS commands. This happens because the software mishandles quotation characters already present in the string, allowing attackers to execute arbitrary commands on the system.

Detection Guidance

Detection involves checking for PeaZip versions before 11.3.0 in non-default configurations. Inspect installed versions and configuration files for vulnerable settings. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could allow an attacker to run unauthorized commands on your system, potentially leading to data theft, system compromise, or further network infiltration. Users running vulnerable versions should update immediately.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR (data protection) and HIPAA (health data security) requirements. Organizations must address it to maintain compliance and avoid penalties.

Mitigation Strategies

Upgrade PeaZip to version 11.3.0 or later. Review and adjust non-default configurations to prevent command injection. Disable or restrict archive processing if unnecessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105050. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart