{"id":"CVE-2026-105050","title":"PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because \"quotation character already used in the string\" is mishandled.","summary":"PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because \"quotation character already used in the string\" is mishandled.","severity":"high","cvss":7.1,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-180"],"vendor":"PeaZip","product":"PeaZip","affected":["PeaZip < 11.3.0"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T23:16:58.093","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105050","references":[{"url":"https://app.secur0.com/certificate/ys3yqg-avrwaq-5ybnwl","label":"cve@mitre.org"},{"url":"https://github.com/peazip/PeaZip/commit/009fc35530e26729863969eddf4c18f1b48331cf","label":"cve@mitre.org"},{"url":"https://github.com/peazip/PeaZip/releases/tag/11.3.0","label":"cve@mitre.org"},{"url":"https://github.com/peazip/PeaZip/tree/sources/peazip-sources","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-02T23:34:57.387Z","slug":"CVE-2026-105050","body":"## Overview\n\nPeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because \"quotation character already used in the string\" is mishandled.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}