bestzip@1.1.1-test1

Uses OS zip command if available (for better performance and speed) or node.js version if there is no system command available. Can be called via node or command line.

  • latest version

    4.0.3

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    1 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the bestzip package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Arbitrary Argument Injection

    bestzip is an Uses OS zip command if avaliable (for better performance and speed) or node.js version if there is no system command avaliable. Can be called via node or command line.

    Affected versions of this package are vulnerable to Arbitrary Argument Injection through the nativeZip function in lib/bestzip.js. An attacker can execute arbitrary commands by supplying a crafted options.destination value and source arguments when using the native Info-ZIP zip backend. The vulnerable command builder passes the destination directly into the zip argv array before the -- separator, so a destination that looks like an option can be interpreted as a flag, allowing later source entries to be parsed as additional options. In applications that forward attacker-controlled archive names and file lists to nativeZip, this can lead to code execution with the Node.js process's privileges.

    How to fix Arbitrary Argument Injection?

    Upgrade bestzip to version 2.2.7, 3.0.3 or higher.

    <2.2.7>=3.0.0 <3.0.3
    • H
    Arbitrary Argument Injection

    bestzip is an Uses OS zip command if avaliable (for better performance and speed) or node.js version if there is no system command avaliable. Can be called via node or command line.

    Affected versions of this package are vulnerable to Arbitrary Argument Injection through the nativeZip process in lib/bestzip.js. An attacker can execute arbitrary commands on the host by supplying source paths that begin with - so they are passed to the native zip CLI as flags instead of filenames. In deployments where untrusted input reaches bestzip, this lets a malicious source list inject zip options such as -T and -TT, causing the process to run attacker-controlled commands with the privileges of the Node.js application.

    How to fix Arbitrary Argument Injection?

    Upgrade bestzip to version 2.2.6, 3.0.2 or higher.

    <2.2.6>=3.0.0 <3.0.2
    • C
    Command Injection

    bestzip is an Uses OS zip command if avaliable (for better performance and speed) or node.js version if there is no system command avaliable. Can be called via node or command line.

    Affected versions of this package are vulnerable to Command Injection via the options param.

    How to fix Command Injection?

    Upgrade bestzip to version 2.1.7 or higher.

    <2.1.7