All findings

CVE-2026-48092 + 7 more high

GitHub's AI-agent index adds eight fixed 7-Zip CVEs

Two GitHub Security Lab pages categorized as AI-agent discoveries document eight 7-Zip CVEs and one additional no-CVE report fixed in 7-Zip 26.01.

Bug class
Heap buffer overflow, memory disclosure, out-of-bounds access, integer overflow, and path traversal
Affected codebase
7-Zip archive and filesystem-image parsers
Credited system
GitHub Security Lab AI agent (unspecified)
Disclosed
May 22, 2026
Attribution
Direct source attribution
Severity
high
Source status: GitHub Security Lab's dedicated AI-agent index categorizes both advisory pages as AI-agent discoveries. The individual pages document fixes and CVEs but name only the researcher, so Bugflation intentionally leaves the particular agent unspecified. High is the editorial cluster maximum because GHSL-2026-140 describes a heap write that may permit arbitrary code execution.

Summary

The larger advisory covers archive and filesystem-image parsing defects across SquashFS, UEFI, UDF, WIM, 7z, and Ar handling, plus a path-traversal issue in a sample application. Seven of its eight GHSL reports have CVE identifiers. The second advisory adds CVE-2026-48095, a heap buffer write in NTFS compressed stream handling with potential arbitrary-code-execution impact.

All nine GHSL reports were fixed in 7-Zip 26.01. The ledger counts the eight public CVE IDs and retains the ninth report as no-CVE context on this campaign page.

Attribution boundary

The AI-assisted classification comes directly from GitHub Security Lab’s official AI-agent index. Because neither individual advisory identifies the agent, the entry does not assign these findings to Taskflow.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.