Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pf92-m78r-h85c

Опубликовано: 09 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

EPSS

Процентиль: 9%
0.00188
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 8.4
nvd
15 дней назад

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

EPSS

Процентиль: 9%
0.00188
Низкий

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-88