CPE
The bestzip package version 2.2.6 and 3.0.2 is vulnerable to argument injection in the nativeZip function, allowing unauthenticated attackers to execute arbitrary commands via malicious input.