GitHub Security Lab disclosed a set of vulnerabilities in 7-Zip affecting archive and filesystem-image parsing, with the most serious issue tracked as CVE-2026-48095 (GHSL-2026-140). The flaw is a heap buffer write overflow in NTFS compressed stream handling, specifically tied to edge-case parsing in GetCuSize(), and could potentially lead to arbitrary code execution when a crafted filesystem image is processed. A proof-of-concept described a malformed sparse NTFS disk image that abuses abnormal cluster sizing and compressed $DATA attributes to trigger the bug.
The broader set of advisories also covered additional defects in parsing formats including SquashFS, UEFI, UDF, WIM, 7z, and Ar, as well as a path traversal issue in a sample application. According to reporting on the disclosures, seven of eight advisories in the set received CVE identifiers, and the issues were addressed in 7-Zip 26.01. GitHub Security Lab also categorized the advisory pages in its AI-agent index as discoveries associated with AI-assisted research, though no specific agent was publicly identified.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Bugflation reported that GitHub Security Lab advisories covered multiple 7-Zip vulnerabilities across archive and filesystem-image parsing, with seven of eight reports assigned CVEs. It stated that all nine referenced GHSL reports were fixed in 7-Zip 26.01.
GitHub Security Lab published its AI Agents index, and the referenced 7-Zip advisory pages were classified there as AI-agent discoveries. The specific agent responsible was not identified in the cited coverage.
GitHub Security Lab published advisory GHSL-2026-140 describing a heap buffer write overflow in 7-Zip's NTFS parsing logic, tracked as CVE-2026-48095. The advisory included a proof-of-concept crafted sparse NTFS disk image intended to trigger the flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securitylab.github.com
Open sourcesecuritylab.github.com
Open sourcebugflation.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.