VYPR
Medium severity6.1NVD Advisory· Published Apr 15, 2025· Updated Jun 17, 2026

CVE-2025-33026

CVE-2025-33026

Description

In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of PeaZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, PeaZip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. NOTE: this is disputed because Mark-of-the-Web propagation can increase risk via security-warning habituation, and because the intended control sphere for file-origin metadata (e.g., HostUrl in Zone.Identifier) may be narrower than that for reading the file's content.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Peazip/PeaZip3 versions
    cpe:2.3:a:peazip:peazip:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:peazip:peazip:*:*:*:*:*:*:*:*range: <=10.4.0
    • (no CPE)range: <=10.4.0
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.