PT-2026-88916 · Nfriedly+1 · Bestzip+1

·

CVE-2026-87794

·

Publicado

2026-09-09

·

Atualizado

2026-09-09

CVSS v4.0

8.6

Alta

VetorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

Exploit

Correção

Argument Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-87794
GHSA-P87M-9567-RGCC
GHSA-XHWX-RCH4-PH2V

Produtos afetados

Bestzip
Node-Bestzip