{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abestzip_projectbestzip2.2.6node.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bestzip_project:bestzip:2.2.6:*:*:*:*:node.js:*:*","cpe:2.3:a:bestzip_project:bestzip:3.0.2:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":8.4,"id":"CVE-2026-87794"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["bestzip (2.2.6, 3.0.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","nodejs","software-supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-87794 describes an argument injection vulnerability within the bestzip Node.js package, specifically affecting versions 2.2.6 and 3.0.2. The vulnerability exists in the nativeZip function, which fails to properly sanitize user-supplied input before passing it to the underlying Info-ZIP backend. An attacker can exploit this by providing a specially crafted destination path or source entry that forces the backend utility to interpret data as command-line flags. This allows for the execution of arbitrary system commands running with the security context and privileges of the Node.js process. This vulnerability is highly relevant for any environment utilizing bestzip for file archival within backend APIs or build pipelines. Remediation requires updating to bestzip version 2.2.7 or 3.0.3, which implement stricter input validation within the nativeZip function.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to execute arbitrary system commands on the host machine. This can lead to full system compromise, exfiltration of sensitive data, or lateral movement within the network, depending on the privileges and environment where the Node.js application is running.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all instances of the bestzip package to version 2.2.7 or 3.0.3 immediately to address CVE-2026-87794.\u003c/li\u003e\n\u003cli\u003eAudit application code to identify if user-controlled input reaches the nativeZip function directly.\u003c/li\u003e\n\u003cli\u003eApply the Principle of Least Privilege by running Node.js applications as low-privileged service accounts to limit the potential impact of command execution vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T10:50:13Z","date_published":"2026-09-09T10:50:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-bestzip-argument-injection/","summary":"The bestzip package version 2.2.6 and 3.0.2 is vulnerable to argument injection in the nativeZip function, allowing unauthenticated attackers to execute arbitrary commands via malicious input.","title":"Argument Injection in bestzip nativeZip Function","url":"https://feed.craftedsignal.io/briefs/2026-09-bestzip-argument-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:bestzip_project:bestzip:2.2.6:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}