Unix Permission Vulnerability in adm-zip Library by CTHackers
CVE-2026-102282

7.1HIGH

Key Information:

Vendor

Cthackers

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-102282?

CVE-2026-102282 is a significant vulnerability found in the adm-zip library, a popular JavaScript module used for creating and extracting ZIP archives in Node.js applications. This vulnerability arises from the way the library handles Unix permission bits when extracting ZIP files with the keepOriginalPermission=true option—a parameter used often during scenarios such as Docker builds or continuous integration (CI) environments, which typically run with elevated privileges. When an attacker crafts a zip file with specific permissions, the extracted files can inherit dangerous permissions, such as setuid, which can lead to privilege escalation. If extracted by a process running as root, the compromised file can later be executed by a lesser-privileged user, allowing the attacker to execute arbitrary code with root privileges. The issue was addressed in version 0.6.1 of the library.

Potential impact of CVE-2026-102282

  1. Privilege Escalation: The most critical risk from this vulnerability is the potential for privilege escalation. If an attacker creates a ZIP file with malicious permissions, it can lead to the execution of their code with root-level access, bypassing standard security controls and allowing complete compromise of the system.

  2. Security Posture Compromise: Organizations that utilize the adm-zip library, particularly in automated environments like CI pipelines or Docker containers, face significant risks as the flaw can be exploited automatically during the extraction of ZIP files. This could result in widespread vulnerabilities across the organization’s infrastructure.

  3. Increased Attack Surface: As adm-zip is commonly used in various Node.js applications, the vulnerability increases the attack surface for potential breaches. Given the nature of modern development practices, this could lead to multiple applications being at risk, amplifying the potential impact across different systems and exposing sensitive data.

Affected Version(s)

adm-zip < 0.6.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.