HIGH 7.1 GitHub

CVE-2026-102282

adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation

## Summary adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact enviro

Affected Products

References

Published: 2026-09-29 · Source: GitHub · Feed updated: 2026-09-30
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-29 via GitHub. Affected: npm/adm-zip <= 0.6.0.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.