{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/lrzsz/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lrzsz:lrzsz:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-105840"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lrzsz (\u003c 0.13.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["lrzsz"],"content_html":"\u003cp\u003eThe lrz utility, part of the lrzsz package used for X/Y/ZMODEM file transfers, contains a path traversal vulnerability (CVE-2026-105840) in its restricted mode. This vulnerability stems from the checkpath() function in src/lrz.c, which fails to adequately filter absolute pathnames. While the software attempts to reject '../' traversal sequences, it does not account for absolute paths when not compiled with the --enable-pubdir option. An attacker acting as a ZMODEM sender can leverage this flaw to write or overwrite files outside the intended destination directory, provided the user running lrz has the necessary file system permissions. This vulnerability is particularly critical in environments where lrz is used to facilitate automated file uploads, as it allows for arbitrary file write scenarios that can lead to remote code execution or system configuration compromise if sensitive files like .ssh/authorized_keys or shell profiles are targeted.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker or a malicious ZMODEM sender to overwrite system files or user-specific configuration files. This can result in privilege escalation, persistence establishment, or remote code execution, depending on the privileges of the account executing the lrz process. The vulnerability affects all systems utilizing lrzsz versions prior to 0.13.0 for ZMODEM file transfers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade lrzsz to version 0.13.0 or later immediately to patch CVE-2026-105840.\u003c/li\u003e\n\u003cli\u003eAudit any automated scripts or services that invoke the lrz binary to ensure they are not exposing the application to untrusted ZMODEM senders.\u003c/li\u003e\n\u003cli\u003eRun the lrz process with the least privilege possible, utilizing restricted user accounts that lack write access to sensitive system directories or user configuration files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T14:56:09Z","date_published":"2026-10-06T14:56:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-lrzsz-path-traversal/","summary":"The lrz receive utility in lrzsz versions before 0.13.0 fails to properly sanitize absolute pathnames in restricted mode, allowing malicious ZMODEM senders to overwrite arbitrary files writable by the receiving user.","title":"Path Traversal in lrzsz lrz Utility","url":"https://feed.craftedsignal.io/briefs/2026-10-lrzsz-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Lrzsz","version":"https://jsonfeed.org/version/1.1"}