PatchSiren

nfriedly CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH nfriedly CVE published 2026-09-09

CVE-2026-87794

CVE-2026-87794 bestzip Argument Injection Vulnerability. The bestzip library versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function. This allows attackers to inject arbitrary arguments to the Info-ZIP backend, potentially leading to arbitrary command execution with Node.js process privileges. Node.js developers and administrators should assess exposure and prioritiz [truncated]