CVE-2026-87794

Source
https://cve.org/CVERecord?id=CVE-2026-87794
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87794.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-87794
Related
  • GHSA-p87m-9567-rgcc
  • GHSA-xhwx-rch4-ph2v
Published
2026-09-09T10:07:27Z
Modified
2026-09-12T03:31:01Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination
Details

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-88"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87794.json"
}
References

Affected packages

Git / github.com/nfriedly/node-bestzip

Affected ranges

Type
GIT
Repo
https://github.com/nfriedly/node-bestzip
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.2.6"
        },
        {
            "fixed": "2.2.7"
        },
        {
            "introduced": "3.0.2"
        },
        {
            "fixed": "3.0.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.2.6
v3.*
v3.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87794.json"