Unix Permission Vulnerability in adm-zip Library by CTHackers
CVE-2026-102282
What is CVE-2026-102282?
CVE-2026-102282 is a significant vulnerability found in the adm-zip library, a popular JavaScript module used for creating and extracting ZIP archives in Node.js applications. This vulnerability arises from the way the library handles Unix permission bits when extracting ZIP files with the keepOriginalPermission=true option—a parameter used often during scenarios such as Docker builds or continuous integration (CI) environments, which typically run with elevated privileges. When an attacker crafts a zip file with specific permissions, the extracted files can inherit dangerous permissions, such as setuid, which can lead to privilege escalation. If extracted by a process running as root, the compromised file can later be executed by a lesser-privileged user, allowing the attacker to execute arbitrary code with root privileges. The issue was addressed in version 0.6.1 of the library.
Potential impact of CVE-2026-102282
-
Privilege Escalation: The most critical risk from this vulnerability is the potential for privilege escalation. If an attacker creates a ZIP file with malicious permissions, it can lead to the execution of their code with root-level access, bypassing standard security controls and allowing complete compromise of the system.
-
Security Posture Compromise: Organizations that utilize the adm-zip library, particularly in automated environments like CI pipelines or Docker containers, face significant risks as the flaw can be exploited automatically during the extraction of ZIP files. This could result in widespread vulnerabilities across the organization’s infrastructure.
-
Increased Attack Surface: As adm-zip is commonly used in various Node.js applications, the vulnerability increases the attack surface for potential breaches. Given the nature of modern development practices, this could lead to multiple applications being at risk, amplifying the potential impact across different systems and exposing sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
adm-zip < 0.6.1
