CVE-2026-87794: Nfriedly Bestzip

High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.

Affected products

  • Nfriedly Bestzip: from 2.2.6, before 2.2.7 (fixed in 2.2.7); from 3.0.2, before 3.0.3 (fixed in 3.0.3)

Published 2026-09-09. Last modified 2026-09-18.