CVE-2026-105050
CVE-2026-105050 is a high-severity vulnerability with a CVSS 4.0 base score of 7.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-180.
Key facts
- Severity: High (CVSS 4.0 base score 7.1)
- EPSS exploit prediction: 1% (42nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-180
- Published:
- Last modified:
Description
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
Frequently asked questions
- What is CVE-2026-105050?
- PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
- How severe is CVE-2026-105050?
- CVE-2026-105050 has a CVSS 4.0 base score of 7.1, rated high severity.
- Is CVE-2026-105050 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (42nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-105050?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-105050 published?
- CVE-2026-105050 was published on 2026-10-02 and last updated on 2026-10-06.
References
- https://app.secur0.com/certificate/ys3yqg-avrwaq-5ybnwl
- https://github.com/peazip/PeaZip/commit/009fc35530e26729863969eddf4c18f1b48331cf
- https://github.com/peazip/PeaZip/releases/tag/11.3.0
- https://github.com/peazip/PeaZip/tree/sources/peazip-sources
Other CWE-180 vulnerabilities
- CVE-2026-15704 — Critical (CVSS 9.8): In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an…
- CVE-2026-24895 — Critical (CVSS 9.8): FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly…
- CVE-2026-73420 — Critical (CVSS 9.1): NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32,…
- CVE-2026-82481 — High (CVSS 8.7): The cohttp package before 6.3.0 for OCaml allows directory traversal.
- CVE-2026-52747 — High (CVSS 8.6): ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to…
- CVE-2026-48721 — High (CVSS 8.6): Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp…