CVE-2026-87794
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbit
CVSS
8.4
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 9 sept 2026 · Última mod.: 9 sept 2026 · CWE-88
Sin historial EPSS suficiente todavía.
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.
- github.comhttps://github.com/nfriedly/node-bestzip
- github.comhttps://github.com/nfriedly/node-bestzip/blob/v3.0.2/lib/bestzip.js
- github.comhttps://github.com/nfriedly/node-bestzip/commit/2adb637b0acb05b8475de7db5af4b86ffcf40aaf
- github.comhttps://github.com/nfriedly/node-bestzip/security/advisories/GHSA-p87m-9567-rgcc
- github.comhttps://github.com/nfriedly/node-bestzip/security/advisories/GHSA-xhwx-rch4-ph2v
- www.npmjs.comhttps://www.npmjs.com/package/bestzip
- www.vulncheck.comhttps://www.vulncheck.com/advisories/bestzip-2.2.6-and-3.0.2-argument-injection-via-the-native-zip-destination
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-8044——
——0CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup configuration parameters.22hCVE-2026-878186.5 MED—
——0GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through distinguishable success or error responses.1dCVE-2026-786355.0 MED5.1%
——2The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended modification of the SSH client's behavior.23hCVE-2026-713779.8 CRÍ24.0%
——7Command Argument Injection Vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 through 09-80-04, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.2dCVE-2026-84256—31.7%
——10An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject2dCVE-2026-86060—33.6%
——10RouterOS contains an argument-handling flaw in the SSH login
path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)1d