bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3. | |
| Title | bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination | |
| First Time appeared |
Bestzip Project
Bestzip Project bestzip |
|
| Weaknesses | CWE-88 | |
| CPEs | cpe:2.3:a:bestzip_project:bestzip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bestzip Project
Bestzip Project bestzip |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-09T10:07:27.925Z
Reserved: 2026-09-09T09:37:54.271Z
Link: CVE-2026-87794
No data.
Status : Received
Published: 2026-09-09T10:22:34.397
Modified: 2026-09-09T10:22:34.397
Link: CVE-2026-87794
No data.
OpenCVE Enrichment
Updated: 2026-09-09T11:30:09Z
Weaknesses