Incorrect Permission Assignment for Critical Resource Affecting adm-zip package, versions <0.6.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ADMZIP-20335419
  • published30 Sept 2026
  • disclosed29 Sept 2026
  • creditAhmed Elmahgob

Introduced: 29 Sep 2026

NewCVE-2026-102282  (opens in a new tab)
CWE-732  (opens in a new tab)

How to fix?

Upgrade adm-zip to version 0.6.1 or higher.

Overview

adm-zip is a JavaScript implementation for zip data compression for NodeJS.

Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource via the fileAttr getter in headers/entryHeader.js, which preserves attacker-controlled Unix special permission bits (setuid 0o4000, setgid 0o2000, and sticky 0o1000) from ZIP archive metadata during extraction. When the keepOriginalPermission option is used and extraction is performed as root, an attacker who controls the ZIP archive can plant a setuid-root binary, achieving local privilege escalation.

Note: This is only exploitable when extraction is performed as a privileged user (e.g., root) with the keepOriginalPermission option enabled.

CVSS Base Scores

version 4.0
version 3.1