Skip to main content

adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation (CVE-2026-102282)

0
High
Published: 09/29/2026 (09/29/2026, 18:24:57 UTC)
Source: GCVE Database
Product: adm-zip

Description

adm-zip versions prior to 0.6.1 have a vulnerability where the extraction process preserves Unix permission bits, including setuid and setgid bits, from untrusted ZIP archives when the keepOriginalPermission flag is enabled. This can lead to local privilege escalation if extraction is performed as root, allowing an attacker to create root-owned setuid files that execute with elevated privileges. The vulnerability arises because adm-zip does not filter out special permission bits before applying them to extracted files. The issue is fixed in versions 0.6.1 and later.

CVSS v3.1

Score 7.1high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected software

npmghsa
adm-zip
Affected versions
<0.6.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 21:21:36 UTC

Technical Analysis

The adm-zip library applies Unix permission bits stored in ZIP entries directly to extracted files when the keepOriginalPermission=true flag is used during extraction. The library reads the mode from the ZIP external attributes and applies it without filtering out special bits such as setuid (0o4000), setgid (0o2000), and sticky bit (0o1000). This allows an attacker to craft a ZIP archive containing files with malicious setuid bits. When extracted as root, these files become root-owned setuid binaries, which can be executed later by less privileged users to escalate privileges. The vulnerability affects adm-zip versions before 0.6.1 and is classified under CWE-732 (incorrect permission assignment).

Potential Impact

An attacker who can supply a malicious ZIP archive to a system that extracts it as root with keepOriginalPermission=true can create root-owned setuid files. These files can be executed by unprivileged users to run code with root privileges, resulting in local privilege escalation. The vulnerability is relevant in environments such as Docker builds, CI pipelines, and privileged install steps where root extraction with permission preservation is common. Default extraction without the flag or extraction by non-root users does not lead to privilege escalation.

Mitigation Recommendations

A fix is available in adm-zip version 0.6.1 and later that masks out special permission bits before applying them to extracted files. Users should upgrade to adm-zip >=0.6.1 to remediate this vulnerability. If upgrading is not immediately possible, avoid using keepOriginalPermission=true when extracting ZIP files from untrusted sources, especially when running as root.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-j5f4-cc29-5x44
Osv Schema Version
1.4.0
Aliases
["CVE-2026-102282"]
Ecosystems
["npm"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6abc27cc680226ef6846f8d6

Added to database: 09/29/2026, 21:04:12 UTC

Last enriched: 09/29/2026, 21:21:36 UTC

Last updated: 09/30/2026, 02:16:03 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses