Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-87794

HIGH NVD
CVSS Score 8.4
Severity HIGH
Published Sep 09, 2026
Vendor unknown

Description

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

References