Argument Injection Vulnerability in bestzip Product by nfriedly
CVE-2026-87794

8.6HIGH

Key Information:

Vendor

Nfriedly

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-87794?

The bestzip versions 2.2.6 and 3.0.2 are susceptible to an argument injection vulnerability within the nativeZip function. This flaw allows attackers to inject harmful arguments into the Info-ZIP backend, leveraging crafted source entries that could lead to arbitrary command execution with Node.js process privileges. Users are encouraged to upgrade to versions 2.2.7 or 3.0.3, which contain essential patches to mitigate this security issue.

Affected Version(s)

bestzip 2.2.6 < 2.2.7

bestzip 3.0.2 < 3.0.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iamabighotdog
.