Executive brief
Lhaz and Lhaz+ are file compression and extraction utilities. A vulnerability in the automatic folder creation feature allows a specially crafted archive file to extract its contents into unintended locations on a user's computer. If a user extracts a malicious archive, files could be placed in sensitive directories, potentially leading to unauthorized system changes or the execution of malicious code.
Technical details
A path traversal vulnerability (CWE-22) exists in Chitora soft Lhaz (v2.6.3 and earlier) and Lhaz+ (v3.6.3 and earlier) within the automatic folder creation logic. When this feature is enabled, the application fails to properly sanitize archive filenames during extraction. An attacker can provide a crafted archive that, when opened by a user, bypasses the intended subfolder creation and writes files to the parent directory or other unintended paths. This requires local user interaction to trigger the extraction of the malicious archive. Patches are available in Lhaz version 2.6.4 and Lhaz+ version 3.6.4.
Affected products
- Chitora soft Lhaz 2.6.3 and earlier
- Chitora soft Lhaz+ 3.6.3 and earlier
Timeline
- 2026-04-15: disclosed: Initial vulnerability information page published by vendor
- 2026-05-11: advisory: JVN advisory published
- 2026-05-12: patched: NVD publication and patch availability confirmed