๐Ÿ” CVE Alert

CVE-2026-105050

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.

CWE CWE-180
Vendor peazip
Product peazip
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for peazip peazip

Be the first to know when new unknown vulnerabilities affecting peazip peazip are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

PeaZip / PeaZip
0 < 11.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/peazip/PeaZip/releases/tag/11.3.0 github.com: https://github.com/peazip/PeaZip/tree/sources/peazip-sources app.secur0.com: https://app.secur0.com/certificate/ys3yqg-avrwaq-5ybnwl github.com: https://github.com/peazip/PeaZip/commit/009fc35530e26729863969eddf4c18f1b48331cf