CVE-2026-87794
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
Schwachstellenklasse
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
Quellen
- https://github.com/nfriedly/node-bestzip
- https://github.com/nfriedly/node-bestzip/blob/v3.0.2/lib/bestzip.js
- https://github.com/nfriedly/node-bestzip/commit/2adb637b0acb05b8475de7db5af4b86ffcf40aaf
- https://github.com/nfriedly/node-bestzip/security/advisories/GHSA-p87m-9567-rgcc
- https://github.com/nfriedly/node-bestzip/security/advisories/GHSA-xhwx-rch4-ph2v
- https://www.npmjs.com/package/bestzip
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.