Path Traversal in lrzsz lrz Utility
The lrz receive utility in lrzsz versions before 0.13.0 fails to properly sanitize absolute pathnames in restricted mode, allowing malicious ZMODEM senders to overwrite arbitrary files writable by the receiving user.
CVE search metadata
CVE search record: CVE-2026-105840. Severity: high. CVSS: 7.5. KEV: no. Product: lrzsz (< 0.13.0). Brief: Path Traversal in lrzsz lrz Utility. Brief link: https://feed.craftedsignal.io/briefs/2026-10-lrzsz-path-traversal/
The lrz utility, part of the lrzsz package used for X/Y/ZMODEM file transfers, contains a path traversal vulnerability (CVE-2026-105840) in its restricted mode. This vulnerability stems from the checkpath() function in src/lrz.c, which fails to adequately filter absolute pathnames. While the software attempts to reject '../' traversal sequences, it does not account for absolute paths when not compiled with the --enable-pubdir option. An attacker acting as a ZMODEM sender can leverage this flaw to write or overwrite files outside the intended destination directory, provided the user running lrz has the necessary file system permissions. This vulnerability is particularly critical in environments where lrz is used to facilitate automated file uploads, as it allows for arbitrary file write scenarios that can lead to remote code execution or system configuration compromise if sensitive files like .ssh/authorized_keys or shell profiles are targeted.
Impact
Successful exploitation allows an unauthenticated remote attacker or a malicious ZMODEM sender to overwrite system files or user-specific configuration files. This can result in privilege escalation, persistence establishment, or remote code execution, depending on the privileges of the account executing the lrz process. The vulnerability affects all systems utilizing lrzsz versions prior to 0.13.0 for ZMODEM file transfers.
Recommendation
- Upgrade lrzsz to version 0.13.0 or later immediately to patch CVE-2026-105840.
- Audit any automated scripts or services that invoke the lrz binary to ensure they are not exposing the application to untrusted ZMODEM senders.
- Run the lrz process with the least privilege possible, utilizing restricted user accounts that lack write access to sensitive system directories or user configuration files.
Immediate actions
Upgrade lrzsz to version 0.13.0 or later.
Mitigations
Upgrade lrzsz to 0.13.0.
CVE-2026-105840