Sceawere

Vulnerability Detail

CVE-2026-102282UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

adm-zip Arbitrary Permission Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
2h ago
Vendor
cthackers
Product
adm-zip
Attack Type
CWE-732: Incorrect Permission Assignment for Critical Resource
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-05T17:17:08.110Z",
  "pubdate": "2026-10-05T17:17:08.110Z",
  "executiveSummary": "A privilege escalation vulnerability exists in the adm-zip library prior to version 0.6.1. The flaw resides in the handling of Unix file permission bits during the extraction of ZIP archives when the keepOriginalPermission flag is enabled.\nBy failing to sanitize setuid, setgid, and sticky bits from archive entry metadata, the library allows an attacker to create malicious ZIP files that, when extracted by a privileged process (such as root in CI/CD pipelines or Docker builds), result in files with dangerous permission modes.\nThis vulnerability can be leveraged to grant an attacker full administrative control over a system. If a root-owned binary is extracted with the setuid bit (mode 04755), a low-privileged user can execute this binary to gain elevated root privileges. The risk is particularly high in automated build environments where administrative privileges are commonly utilized. No authentication is required to craft the malicious payload, provided the target process is coerced into extracting a malicious archive.\nExploitation requires the victim to extract a maliciously crafted archive using the vulnerable library configuration. Impact includes total system compromise via privilege escalation.",
  "technicalDetails": "The vulnerability originates from the unsafe application of filesystem metadata during the extraction process in the adm-zip library. Specifically, when the keepOriginalPermission option is set to true during calls to extractAllTo() or extractEntryTo(), the library retrieves the Unix permission mode stored within the ZIP file header.\nThe core issue is a lack of input sanitization regarding the file mode bits. The library passes these raw bits directly to the Node.js fs.chmodSync() function without filtering out sensitive setuid (04000), setgid (02000), and sticky bits (01000).\nIn a standard Linux/Unix environment, the setuid bit allows a user to execute an executable with the permissions of the file owner. Because many automated environments, such as Docker containers or CI/CD runner processes, execute extraction tasks as the root user, any file extracted with the setuid bit set will inherit the root owner and elevated execution context.\nThe attack flow follows these steps: 1. An attacker constructs a ZIP archive where an entry is configured with the setuid bit set (e.g., 04755). 2. The attacker delivers this archive to a system or automated process that uses adm-zip to extract contents with the keepOriginalPermission flag enabled. 3. Upon execution, the library performs a chmodSync() operation on the extracted binary, applying the malicious mode bit. 4. The system now contains a root-owned file with the setuid attribute. 5. A low-privileged attacker executes the malicious binary, causing the kernel to elevate the process context to root, resulting in full arbitrary code execution with administrative privileges.\nThis vulnerability affects all versions of adm-zip prior to 0.6.1. The flaw is inherent in the library's design choice to trust archive metadata implicitly rather than enforcing a whitelist of permissible file attributes. The impact is significant in environments where automated processes operate with broad filesystem permissions, as the escalation path is direct and does not require complex side-channel or memory corruption exploits. The vulnerability is effectively a semantic flaw in how the library maps internal archive metadata to OS-level filesystem security controls."
}
CVE-2026-102282: adm-zip Arbitrary Permission Escalation (HIGH Severity, CVSS: 7.1) | Sceawere