adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation (CVE-2026-102282)
adm-zip versions prior to 0.6.1 have a vulnerability where the extraction process preserves Unix permission bits, including setuid and setgid bits, from untrusted ZIP archives when the keepOriginalPermission flag is enabled. This can lead to local privilege escalation if extraction is performed as root, allowing an attacker to create root-owned setuid files that execute with elevated privileges. The vulnerability arises because adm-zip does not filter out special permission bits before applying them to extracted files. The issue is fixed in versions 0.6.1 and later.
AI Analysis
Technical Summary
The adm-zip library applies Unix permission bits stored in ZIP entries directly to extracted files when the keepOriginalPermission=true flag is used during extraction. The library reads the mode from the ZIP external attributes and applies it without filtering out special bits such as setuid (0o4000), setgid (0o2000), and sticky bit (0o1000). This allows an attacker to craft a ZIP archive containing files with malicious setuid bits. When extracted as root, these files become root-owned setuid binaries, which can be executed later by less privileged users to escalate privileges. The vulnerability affects adm-zip versions before 0.6.1 and is classified under CWE-732 (incorrect permission assignment).
Potential Impact
An attacker who can supply a malicious ZIP archive to a system that extracts it as root with keepOriginalPermission=true can create root-owned setuid files. These files can be executed by unprivileged users to run code with root privileges, resulting in local privilege escalation. The vulnerability is relevant in environments such as Docker builds, CI pipelines, and privileged install steps where root extraction with permission preservation is common. Default extraction without the flag or extraction by non-root users does not lead to privilege escalation.
Mitigation Recommendations
A fix is available in adm-zip version 0.6.1 and later that masks out special permission bits before applying them to extracted files. Users should upgrade to adm-zip >=0.6.1 to remediate this vulnerability. If upgrading is not immediately possible, avoid using keepOriginalPermission=true when extracting ZIP files from untrusted sources, especially when running as root.
adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation (CVE-2026-102282)
Description
adm-zip versions prior to 0.6.1 have a vulnerability where the extraction process preserves Unix permission bits, including setuid and setgid bits, from untrusted ZIP archives when the keepOriginalPermission flag is enabled. This can lead to local privilege escalation if extraction is performed as root, allowing an attacker to create root-owned setuid files that execute with elevated privileges. The vulnerability arises because adm-zip does not filter out special permission bits before applying them to extracted files. The issue is fixed in versions 0.6.1 and later.
CVSS v3.1
Score 7.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The adm-zip library applies Unix permission bits stored in ZIP entries directly to extracted files when the keepOriginalPermission=true flag is used during extraction. The library reads the mode from the ZIP external attributes and applies it without filtering out special bits such as setuid (0o4000), setgid (0o2000), and sticky bit (0o1000). This allows an attacker to craft a ZIP archive containing files with malicious setuid bits. When extracted as root, these files become root-owned setuid binaries, which can be executed later by less privileged users to escalate privileges. The vulnerability affects adm-zip versions before 0.6.1 and is classified under CWE-732 (incorrect permission assignment).
Potential Impact
An attacker who can supply a malicious ZIP archive to a system that extracts it as root with keepOriginalPermission=true can create root-owned setuid files. These files can be executed by unprivileged users to run code with root privileges, resulting in local privilege escalation. The vulnerability is relevant in environments such as Docker builds, CI pipelines, and privileged install steps where root extraction with permission preservation is common. Default extraction without the flag or extraction by non-root users does not lead to privilege escalation.
Mitigation Recommendations
A fix is available in adm-zip version 0.6.1 and later that masks out special permission bits before applying them to extracted files. Users should upgrade to adm-zip >=0.6.1 to remediate this vulnerability. If upgrading is not immediately possible, avoid using keepOriginalPermission=true when extracting ZIP files from untrusted sources, especially when running as root.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-j5f4-cc29-5x44
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-102282"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6abc27cc680226ef6846f8d6
Added to database: 09/29/2026, 21:04:12 UTC
Last enriched: 09/29/2026, 21:21:36 UTC
Last updated: 09/30/2026, 02:16:03 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.