VDB
Sign up
CRITICAL

GHSA-4qqc-mp5f-ccv4

Command Injection in bestzip

Quick fix

GHSA-4qqc-mp5f-ccv4 — bestzip: upgrade to the fixed version with the command below.

npm install bestzip@2.1.7

Details

Versions of `bestzip` prior to 2.1.7 are vulnerable to Command Injection. The package fails to sanitize input rules and passes it directly to an `exec` call on the `zip` function . This may allow attackers to execute arbitrary code in the system as long as the values of `destination` is user-controlled. This only affects users with a native `zip` command available. The following examples demonstrate the issue from the CLI and also programatically: - `bestzip test.zip 'sourcefile; mkdir folder'` - `zip({ source: 'sourcefile', destination: './test.zip; mkdir folder' })`

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/bestzip
Introduced in: 0Fixed in: 2.1.7
Fixnpm install bestzip@2.1.7

References