HIGH 7.1 GitHub
CVE-2026-102282
adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
## Summary
adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact enviro
Affected Products
- npm/adm-zip <= 0.6.0
References
- https://github.com/advisories/GHSA-j5f4-cc29-5x44
- https://github.com/cthackers/adm-zip/security/advisories/GHSA-j5f4-cc29-5x44
- https://github.com/cthackers/adm-zip/commit/6a63c339b83c52915483efacda517660a7a7bf87
- https://github.com/cthackers/adm-zip/releases/tag/v0.6.1
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-29 via GitHub. Affected: npm/adm-zip <= 0.6.0.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.