High severity8.4NVD Advisory· Published Sep 9, 2026
CVE-2026-87794
CVE-2026-87794
Description
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
Affected products
2- Range: 2.2.6, 3.0.2
- Package: https://npmjs.com/package/bestzip
Patches
Vulnerability mechanics
References
6- github.com/nfriedly/node-bestzip/blob/v3.0.2/lib/bestzip.jsnvd
- github.com/nfriedly/node-bestzip/commit/2adb637b0acb05b8475de7db5af4b86ffcf40aafnvd
- github.com/nfriedly/node-bestzip/security/advisories/GHSA-p87m-9567-rgccnvd
- github.com/nfriedly/node-bestzip/security/advisories/GHSA-xhwx-rch4-ph2vnvd
- www.npmjs.com/package/bestzipnvd
- www.vulncheck.com/advisories/bestzip-2.2.6-and-3.0.2-argument-injection-via-the-native-zip-destinationnvd
News mentions
0No linked articles in our index yet.