adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j5f4-cc29-5x44 | adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cthackers
Cthackers adm-zip |
|
| Vendors & Products |
Cthackers
Cthackers adm-zip |
Mon, 05 Oct 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue. | |
| Title | adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T17:00:00.250Z
Reserved: 2026-09-28T20:11:16.659Z
Link: CVE-2026-102282
No data.
Status : Deferred
Published: 2026-10-05T17:17:08.110
Modified: 2026-10-05T17:17:09.230
Link: CVE-2026-102282
No data.
OpenCVE Enrichment
Updated: 2026-10-05T19:00:13Z
Weaknesses
Github GHSA