{"id":"CVE-2026-87794","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-87794","summary":"bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers…","details":"bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.","published":"2026-09-09T10:22:34.397","modified":"2026-09-09T10:22:34.397","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/nfriedly/node-bestzip/commit/2adb637b0acb05b8475de7db5af4b86ffcf40aaf","label":"nfriedly/node-bestzip@2adb637"},"references":[{"type":"WEB","url":"https://github.com/nfriedly/node-bestzip"},{"type":"WEB","url":"https://github.com/nfriedly/node-bestzip/blob/v3.0.2/lib/bestzip.js"},{"type":"WEB","url":"https://github.com/nfriedly/node-bestzip/commit/2adb637b0acb05b8475de7db5af4b86ffcf40aaf"},{"type":"WEB","url":"https://github.com/nfriedly/node-bestzip/security/advisories/GHSA-p87m-9567-rgcc"},{"type":"WEB","url":"https://github.com/nfriedly/node-bestzip/security/advisories/GHSA-xhwx-rch4-ph2v"},{"type":"WEB","url":"https://www.npmjs.com/package/bestzip"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/bestzip-2.2.6-and-3.0.2-argument-injection-via-the-native-zip-destination"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T10:22:34.397"}}