Sceawere

Vulnerability Detail

CVE-2026-105841UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

lrzsz OS Command Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
11h ago
Vendor
Uwe Ohse
Product
lrzsz
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by supplying crafted filenames. When lrz runs under a suffixed name such as lrztar, procheader() in src/lrz.c passes the unescaped ZMODEM/YMODEM filename to popen(), so shell metacharacters execute as the receiving user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-06T14:17:41.460Z",
  "pubdate": "2026-10-06T14:17:41.460Z",
  "executiveSummary": "The lrzsz utility, specifically versions prior to 0.13.0, is susceptible to an OS command injection vulnerability within the lrz receive utility when executing in pipe mode. This vulnerability arises from improper handling of filenames provided by a remote sender during a ZMODEM or YMODEM transfer.\nThe vulnerability occurs when lrz is invoked via a suffixed alias, such as lrztar. In this configuration, the application fails to adequately sanitize the filename before passing it to the popen() function. A remote attacker can craft malicious filenames containing shell metacharacters to achieve arbitrary command execution on the target host.\nThe impact of successful exploitation is critical, as it grants the attacker the ability to execute arbitrary commands with the privileges of the user running the lrz process. This can lead to unauthorized data access, system compromise, or further exploitation within the network. The vulnerability requires interaction with a remote sender, making it exploitable in environments where untrusted file transfers occur. Organizations should prioritize updating to a patched version of lrzsz or implementing strict input validation and access controls for transfer utilities.",
  "technicalDetails": "The root cause of this vulnerability lies in the implementation of the procheader() function within src/lrz.c. When the lrz executable is launched with a suffix (e.g., lrztar), the program enters a mode where it handles incoming ZMODEM/YMODEM streams by interpreting the metadata associated with the file transfer.\nSpecifically, when lrz operates under these aliased conditions, the filename string extracted from the ZMODEM/YMODEM header is not subjected to necessary shell escaping or sanitization routines. This raw, attacker-controlled string is subsequently passed directly as an argument to the popen() function. Because popen() invokes the system shell (/bin/sh) to execute the provided command string, any shell metacharacters (such as backticks, semicolons, or pipe symbols) embedded within the crafted filename are interpreted and executed by the shell.\nThe attack flow proceeds as follows: 1) The attacker initiates a ZMODEM or YMODEM file transfer to a target host running a vulnerable version of lrzsz. 2) The attacker crafts a filename containing shell injection payloads, such as '; [command] #'. 3) The target lrz instance receives the metadata packet containing the malicious filename. 4) The procheader() function processes this filename and invokes popen() to handle the file reception or processing. 5) The shell interprets the malicious filename as part of a command sequence, executing the attacker-supplied instructions. 6) The resulting command executes with the privileges of the user who initiated the lrz session.\nThis vulnerability is particularly dangerous because it bypasses conventional input validation filters that might exist at higher application layers. Since the injection occurs at the point of system interaction, the threat surface includes any network connection accepting ZMODEM or YMODEM transfers. There is no requirement for prior authentication to the system, as the vulnerability is triggered by the reception of an unsolicited or malicious file stream. The post-exploitation impact is severe, enabling attackers to gain persistence, escalate privileges if the lrz process is running with elevated permissions, or pivot to internal network resources. All versions prior to 0.13.0 are considered vulnerable."
}
CVE-2026-105841: lrzsz OS Command Injection Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere