CVE-2026-105841: high-severity vulnerability in Uwe Ohse lrzsz
lrzsz before 0.13.0 OS Command Injection via lrz Pipe Mode
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.7epss 0.9%
exploitation probability
0.9%top 40% of all CVEs
observed exploitation
nono source reports it
lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs under a suffixed name such as lrztar, procheader() in src/lrz.c passes the unescaped ZMODEM/YMODEM filename to popen(), so shell metacharacters execute as the receiving user.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Uwe Ohse · lrzszRelated CVEs — Uwe Ohse lrzsz
In the same product, most dangerous first.