Skip to content
Lrzsz Vulnerabilities: OS Command Injection and Path Traversal Risks

Lrzsz Vulnerabilities: OS Command Injection and Path Traversal Risks

First seen 6 Oct 2026, 21:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 22:57 UTC
  • •Two critical vulnerabilities in lrzsz before version 0.13.0: OS command injection and path traversal.
  • •CWE-78 and CWE-22 vulnerabilities could allow attackers to execute commands and access unauthorized files.
  • •Users are advised to upgrade to lrzsz version 0.13.0 to mitigate these risks.

Two vulnerabilities have been identified in lrzsz versions prior to 0.13.0. The first, a command injection flaw (CWE-78), allows attackers to execute arbitrary OS commands via the lrz pipe mode. The second, a path traversal vulnerability (CWE-22), enables unauthorized file access through the lrz restricted mode checkpath. Both vulnerabilities could potentially be exploited by attackers to compromise systems using lrzsz. Security updates have been released to address these issues. Users are urged to upgrade to version 0.13.0 or later to mitigate risks. No has been reported as of now, but the vulnerabilities are significant enough to warrant immediate attention from system administrators.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-06
Vulnerabilities disclosed
Lrzsz vulnerabilities involving OS command injection and path traversal were disclosed, affecting versions before 0.13.0.
VulnCheck
2026-10-06
Security updates released
Lrzsz released version 0.13.0 to address the identified vulnerabilities, urging users to upgrade immediately.
VulnCheck

More articles in this cluster (2)

Common questions

Which versions of lrzsz are affected?
All versions prior to 0.13.0 are affected by these vulnerabilities.
Have these vulnerabilities been exploited in the wild?
No active exploitation has been reported as of now.
What should users do to protect their systems?
Users should upgrade to lrzsz version 0.13.0 or later to mitigate the risks associated with these vulnerabilities.