Description
adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue.
Published: 2026-10-05
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Upgrade
AI Analysis

Impact

The vulnerability in adm-zip allows an attacker to create a ZIP archive that includes file entries with set‑uid or set‑gid bits. When the library extracts these entries using the keepOriginalPermission option, it applies the exact permission bits to the created file without filtering out the SUID/SGID bits. If the extraction is performed while the process runs as root— which is common in Docker builds, CI runners, and privileged installation steps—the resulting root‑owned binary can later be executed by an unprivileged user, giving that user root privileges. This flaw is a classic example of improper permission handling (CWE‑732).

Affected Systems

The issue affects the Node.js library adm‑zip from cthackers. Versions prior to 0.6.1 are vulnerable, as they do not strip set‑uid/set‑gid bits from extracted entries. All releases following v0.6.1 contain the fix and should be used.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity Local Privilege Escalation risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a malicious ZIP to an application that extracts archives as root with keepOriginalPermission enabled—a scenario often encountered in automated build environments or CI pipelines. Once the set‑uid binary is created, a normal user can run it to gain root privileges, making the vulnerability potentially critical in these contexts.

Generated by OpenCVE AI on October 5, 2026 at 18:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade adm‑zip to version 0.6.1 or later
  • If an upgrade is not possible, configure the extraction to run under a non‑root user or disable the keepOriginalPermission flag
  • Verify that no untrusted ZIP archives are processed in privileged sessions

Generated by OpenCVE AI on October 5, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j5f4-cc29-5x44 adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
History

Mon, 05 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Cthackers
Cthackers adm-zip
Vendors & Products Cthackers
Cthackers adm-zip

Mon, 05 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue.
Title adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Cthackers Adm-zip
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T17:00:00.250Z

Reserved: 2026-09-28T20:11:16.659Z

Link: CVE-2026-102282

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:08.110

Modified: 2026-10-05T17:17:09.230

Link: CVE-2026-102282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T19:00:13Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource