Impact
adm-zip is a Node.js library that reads ZIP archives. In versions earlier than 0.6.1 the getData() method allocates a buffer using the uncompressed size reported in the ZIP central directory without verifying that it matches the actual decompressed size. A maliciously crafted ZIP can declare a multi‑gigabyte uncompressed size, forcing Buffer.alloc and the decompression routine to allocate large amounts of memory before detecting the CRC error. This can exhaust system memory, cause the operating system to kill the process, or lead to prolonged resource starvation, effectively disabling the application.
Affected Systems
The vulnerability affects the adm-zip package supplied by cthackers. Any Node.js application that imports and uses adm-zip prior to version 0.6.1 is susceptible. This includes libraries or web applications that accept uploads of ZIP files from untrusted users.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. An EPSS score of <1% and the fact that the flaw is not listed in CISA KEV suggest no confirmed widespread exploitation. However, the issue can be exploited remotely if an application accepts ZIPs from external parties. Attackers can craft a malicious archive, host it, and trigger the vulnerability by having the target application process the archive, leading to memory exhaustion or termination of the process. The lack of input validation and the direct buffer allocation make the attack straightforward for a knowledgeable adversary.
OpenCVE Enrichment
Github GHSA