Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-87794

Опубликовано: 09 сент. 2026
Источник: nvd
CVSS3: 8.4
EPSS Низкий

Описание

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

EPSS

Процентиль: 9%
0.00188
Низкий

8.4 High

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 8.4
github
15 дней назад

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

EPSS

Процентиль: 9%
0.00188
Низкий

8.4 High

CVSS3

Дефекты

CWE-88