Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j5f4-cc29-5x44 | adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation |
Mon, 05 Oct 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue. | |
| Title | adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T17:00:00.250Z
Reserved: 2026-09-28T20:11:16.659Z
Link: CVE-2026-102282
No data.
Status : Deferred
Published: 2026-10-05T17:17:08.110
Modified: 2026-10-05T17:17:09.230
Link: CVE-2026-102282
No data.
OpenCVE Enrichment
Updated: 2026-10-05T18:30:19Z
Github GHSA