CVE-2026-87794

    Dashboard / Vulnerabilities / CVE-2026-87794

    CVE-2026-87794

    Published: 9 Sept 2026Last Modified: 12 Sept 2026

    Summary: bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination

    Details: bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 4b301c1111f516f1f6ec7cde1879ed13f3da2244
    Fixed -None

    Affected versions

    v2.2.6

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-87794 | CVE-DB