← Back to browse
·
API
CVE-2020-7730
Severity
CRITICAL
CVSS
9.8
EPSS
0.03145
Risk score
40.3
CISA KEV
No
PoC
No
Published
2020-09-04
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-0979, GHSA-6XV6-JPVW-CX6Q
Products
n/a:bestzip unspecified <2.1.7
Sources
euvd
EUVD-2021-0979
Description
The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.
References
https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-0979
https://snyk.io/vuln/SNYK-JS-BESTZIP-609371
https://github.com/nfriedly/node-bestzip/commit/45d4a901478c6a8f396c8b959dd6cf8fd3f955b6