bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
nfriedly · bestzipReferences
https://github.com/nfriedly/node-bestziphttps://github.com/nfriedly/node-bestzip/blob/v3.0.2/lib/bestzip.jshttps://github.com/nfriedly/node-bestzip/commit/2adb637b0acb05b8475de7db5af4b86ffcf40aafhttps://github.com/nfriedly/node-bestzip/security/advisories/GHSA-p87m-9567-rgcchttps://github.com/nfriedly/node-bestzip/security/advisories/GHSA-xhwx-rch4-ph2vhttps://www.npmjs.com/package/bestziphttps://www.vulncheck.com/advisories/bestzip-2.2.6-and-3.0.2-argument-injection-via-the-native-zip-destination