PT-2026-102974 · Npm · Adm-Zip

CVE-2026-102282

·

Published

2026-09-29

·

Updated

2026-10-03

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions adm-zip version 0.6.0
Description An issue exists where the software applies Unix permission bits from a zip entry directly to an extracted file using the fs.chmodSync() function when the keepOriginalPermission flag is set to true in the extractAllTo() or extractEntryTo() functions. The software fails to filter out setuid, setgid, and sticky bits, allowing a specially crafted zip file to create a binary with mode 04755. If the extraction process is performed by a root user—common in Docker builds, CI runners, and privileged installation steps—the resulting root-owned setuid file can be executed by a lower-privileged user to achieve root execution. This issue also affects directory entries, where a setgid bit can lead to group inheritance for new files within that directory.
Recommendations For version 0.6.0, avoid using the keepOriginalPermission flag when extracting untrusted archives while running as root. As a temporary mitigation, restrict the use of the extractAllTo() and extractEntryTo() functions with the keepOriginalPermission parameter set to true until a patch is available.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102282
GHSA-J5F4-CC29-5X44

Affected Products

Adm-Zip