CyberRota Analysis
AI-GeneratedBestzip versions 2.2.6 and 3.0.2 are vulnerable to an argument injection flaw in the nativeZip function, enabling attackers to inject arbitrary arguments into the Info-ZIP backend. This vulnerability allows for the execution of arbitrary commands with Node.js process privileges, posing a significant risk to systems using these versions. Organizations utilizing these versions should prioritize upgrading to 2.2.7 or 3.0.3 to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands with Node.js process privileges. Fixed in 2.2.7 and 3.0.3.