Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade adm-zip to version 0.6.1 or higher.
adm-zip is a JavaScript implementation for zip data compression for NodeJS.
Affected versions of this package are vulnerable to Incorrect Permission Assignment for Critical Resource via the fileAttr getter in headers/entryHeader.js, which preserves attacker-controlled Unix special permission bits (setuid 0o4000, setgid 0o2000, and sticky 0o1000) from ZIP archive metadata during extraction. When the keepOriginalPermission option is used and extraction is performed as root, an attacker who controls the ZIP archive can plant a setuid-root binary, achieving local privilege escalation.
Note: This is only exploitable when extraction is performed as a privileged user (e.g., root) with the keepOriginalPermission option enabled.