๐Ÿ” CVE Alert

CVE-2026-102282

HIGH 7.1

adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` โ€” and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps โ€” the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue.

CWE CWE-732
Vendor cthackers
Product adm-zip
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for cthackers adm-zip

Be the first to know when new high vulnerabilities affecting cthackers adm-zip are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

cthackers / adm-zip
< 0.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cthackers/adm-zip/security/advisories/GHSA-j5f4-cc29-5x44 github.com: https://github.com/cthackers/adm-zip/commit/6a63c339b83c52915483efacda517660a7a7bf87 github.com: https://github.com/cthackers/adm-zip/releases/tag/v0.6.1