PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because quotation character already used in the string is mishandled.
The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.