---
id: CVE-2026-105841
title: >-
  lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz
  receive utility's pipe mode that allows remote senders to execute commands by
  supplying crafted filenames
summary: >-
  lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz
  receive utility's pipe mode that allows remote senders to execute commands by
  supplying crafted filenames. When lrz runs under a suffixed name such as
  lrztar, …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Uwe Ohse
product: lrzsz
affected:
  - lrzsz < 0.13.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T15:25:00.650'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105841'
references:
  - url: 'https://ohse.de/uwe/software/lrzsz.html'
    label: disclosure@vulncheck.com
  - url: 'https://ohse.de/uwe/software/lrzsz/NEWS-0.13.0.html'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/lrzsz-before-0.13.0-os-command-injection-via-lrz-pipe-mode
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-06T13:56:33.353808Z'
ingestedAt: '2026-10-06T14:00:19.148Z'
---

## Overview

lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs under a suffixed name such as lrztar, procheader() in src/lrz.c passes the unescaped ZMODEM/YMODEM filename to popen(), so shell metacharacters execute as the receiving user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
