Impact
The vulnerability in adm-zip allows an attacker to create a ZIP archive that includes file entries with set‑uid or set‑gid bits. When the library extracts these entries using the keepOriginalPermission option, it applies the exact permission bits to the created file without filtering out the SUID/SGID bits. If the extraction is performed while the process runs as root— which is common in Docker builds, CI runners, and privileged installation steps—the resulting root‑owned binary can later be executed by an unprivileged user, giving that user root privileges. This flaw is a classic example of improper permission handling (CWE‑732).
Affected Systems
The issue affects the Node.js library adm‑zip from cthackers. Versions prior to 0.6.1 are vulnerable, as they do not strip set‑uid/set‑gid bits from extracted entries. All releases following v0.6.1 contain the fix and should be used.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity Local Privilege Escalation risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a malicious ZIP to an application that extracts archives as root with keepOriginalPermission enabled—a scenario often encountered in automated build environments or CI pipelines. Once the set‑uid binary is created, a normal user can run it to gain root privileges, making the vulnerability potentially critical in these contexts.
OpenCVE Enrichment
Github GHSA