Symlink Attack Affecting adm-zip package, versions >=0.5.9


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.13% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ADMZIP-19276676
  • published27 Aug 2026
  • disclosed24 Aug 2026
  • creditMuhammad Sobirov

Introduced: 24 Aug 2026

NewCVE-2026-76845  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

There is no fixed version for adm-zip.

Overview

adm-zip is a JavaScript implementation for zip data compression for NodeJS.

Affected versions of this package are vulnerable to Symlink Attack through the extractAllTo, extractAllToAsync, and extractEntryTo code paths in util/utils.js. An attacker can write attacker-controlled contents outside the extraction root by placing a symbolic link inside the destination directory and then supplying an archive entry that is extracted with overwrite enabled. This can replace any file the extracting process is allowed to write, breaking the integrity of files in shared, reused, or predictable extraction locations such as temporary directories or CI workspaces.

CVSS Base Scores

version 4.0
version 3.1