CVE-2026-102282
Deferred Deferred - Pending Action

Setuid Privilege Escalation in adm-zip Library

Vulnerability report for CVE-2026-102282, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` β€” and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps β€” the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cthackers adm-zip < 0.6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the adm-zip JavaScript library before version 0.6.1. When extracting ZIP files with the keepOriginalPermission flag set to true, the library applies Unix permission bits directly from the ZIP entry to the extracted file without filtering out setuid, setgid, or sticky bits. An attacker can craft a malicious ZIP file containing a binary with setuid permissions (e.g., mode 04755). If extracted as root, this creates a root-owned setuid file that can later be executed by a lower-privileged user, leading to privilege escalation.

The fix in version 0.6.1 strips these special bits by masking only the 9 permission bits (rwxrwxrwx) instead of preserving all special bits.

Detection Guidance

Check if adm-zip version 0.6.0 or earlier is installed using npm list adm-zip. If installed, verify if your application uses the keepOriginalPermission=true flag during extraction. Inspect extracted files for setuid/setgid bits using ls -l to check for permissions like 4755 or 2755.

Impact Analysis

If you use adm-zip versions before 0.6.1 to extract untrusted ZIP files with keepOriginalPermission=true while running as root (common in Docker builds, CI runners, or privileged installations), an attacker could craft a malicious ZIP file that installs a setuid-root binary. When executed by a lower-privileged user, this binary could run with root privileges, allowing the attacker to gain control of your system.

Compliance Impact

This vulnerability primarily enables local privilege escalation, which could lead to unauthorized system access. While not directly violating GDPR or HIPAA, such access could result in unauthorized data exposure or modification, potentially violating these regulations if sensitive data is involved.

Mitigation Strategies

Upgrade adm-zip to version 0.6.1 or later. Avoid using the keepOriginalPermission=true flag unless absolutely necessary. If extraction must run as root, validate ZIP contents before extraction and restrict permissions on extracted files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102282. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart