bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
History

Wed, 09 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
Title bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination
First Time appeared Bestzip Project
Bestzip Project bestzip
Weaknesses CWE-88
CPEs cpe:2.3:a:bestzip_project:bestzip:*:*:*:*:*:*:*:*
Vendors & Products Bestzip Project
Bestzip Project bestzip
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-09-09T10:07:27.925Z

Updated: 2026-09-09T10:07:27.925Z

Reserved: 2026-09-09T09:37:54.271Z

Link: CVE-2026-87794

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T10:22:34.397

Modified: 2026-09-09T10:22:34.397

Link: CVE-2026-87794

cve-icon Redhat

No data.