HIGH
nfriedly
CVE published 2026-09-09
CVE-2026-87794
CVE-2026-87794 bestzip Argument Injection Vulnerability. The bestzip library versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function. This allows attackers to inject arbitrary arguments to the Info-ZIP backend, potentially leading to arbitrary command execution with Node.js process privileges. Node.js developers and administrators should assess exposure and prioritiz [truncated]