OS Command Injection Vulnerability in PeaZip Software
CVE-2026-105050

7.1HIGH

Key Information:

Vendor

Peazip

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-105050?

PeaZip, prior to version 11.3.0, is susceptible to an OS command injection that can occur due to improper handling of quotation characters within filenames in archives. This flaw may allow attackers to execute arbitrary commands on the host operating system when the application is configured in a non-default manner. Users of affected versions are encouraged to upgrade to the latest release to mitigate potential risks.

Affected Version(s)

PeaZip 0 < 11.3.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.