High severity7.5NVD Advisory· Published Oct 6, 2026
CVE-2026-105840
CVE-2026-105840
Description
lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolute pathnames. Because checkpath() in src/lrz.c only rejects '../' sequences unless built with --enable-pubdir, attackers can send files named with absolute paths to overwrite any file writable by the receiving user.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.