PT-2026-102974 · Npm · Adm-Zip
CVE-2026-102282
·
Published
2026-09-29
·
Updated
2026-10-03
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
adm-zip version 0.6.0
Description
An issue exists where the software applies Unix permission bits from a zip entry directly to an extracted file using the
fs.chmodSync() function when the keepOriginalPermission flag is set to true in the extractAllTo() or extractEntryTo() functions. The software fails to filter out setuid, setgid, and sticky bits, allowing a specially crafted zip file to create a binary with mode 04755. If the extraction process is performed by a root user—common in Docker builds, CI runners, and privileged installation steps—the resulting root-owned setuid file can be executed by a lower-privileged user to achieve root execution. This issue also affects directory entries, where a setgid bit can lead to group inheritance for new files within that directory.Recommendations
For version 0.6.0, avoid using the
keepOriginalPermission flag when extracting untrusted archives while running as root.
As a temporary mitigation, restrict the use of the extractAllTo() and extractEntryTo() functions with the keepOriginalPermission parameter set to true until a patch is available.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adm-Zip