Summary
The larger advisory covers archive and filesystem-image parsing defects across SquashFS, UEFI, UDF, WIM, 7z, and Ar handling, plus a path-traversal issue in a sample application. Seven of its eight GHSL reports have CVE identifiers. The second advisory adds CVE-2026-48095, a heap buffer write in NTFS compressed stream handling with potential arbitrary-code-execution impact.
All nine GHSL reports were fixed in 7-Zip 26.01. The ledger counts the eight public CVE IDs and retains the ninth report as no-CVE context on this campaign page.
Attribution boundary
The AI-assisted classification comes directly from GitHub Security Lab’s official AI-agent index. Because neither individual advisory identifies the agent, the entry does not assign these findings to Taskflow.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.