Vulnerability Intelligence Report
lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath()
CVE-2026-105840
lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files outside the current directory using absolute pathnames. Because checkpath() in src/lrz.c only rejects '../' sequences unless built with --enable-pubdir, attackers can send files named with absolute paths to overwrite any file writable by the receiving user.
Path Traversal
No Active Exploit Signals
CVSS Base Score
7.7
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Uwe Ohse | lrzsz | 0 < 0.13.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Vulnerability Class
Path Traversal
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-10-05T22:00:10 |
| Published | 2026-10-06T13:35:46 |
| Patch Date | 2026-09-30 |
| Last Updated | 2026-10-06T13:35:46 |
Community Chatter & Buzz