VYPR
Vendor

Nfriedly

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2026-87794HigSep 9, 2026
    risk 0.48cvss 8.4epss 0.00

    bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute…

  • CVE-2026-80427HigAug 26, 2026
    risk 0.48cvss 8.4epss 0.00

    bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so any source entry beginning with a hyphen…