CVE-2026-76845: Improper Link Resolution Before File Access ('Link Following') in cthackers adm-zip
Description
CVE-2026-76845 is a vulnerability in cthackers adm-zip versions 0.5.9 through 0.6.0 where symbolic links are followed during archive extraction, allowing an attacker to write files outside the intended extraction directory. This occurs because the sanitization only compares string paths without properly preventing symbolic link traversal, and the extraction functions open files without safeguards against link following. An attacker who can place a symbolic link inside a shared or predictable extraction directory can cause arbitrary file overwrite if the extracting process has write permissions and overwrite is enabled.
CVSS v4.0
Score 6.8medium
Affected software
cthackers
adm-zip
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The adm-zip library versions 0.5.9 to 0.6.0 improperly handle symbolic links during archive extraction. The utility function Utils.sanitize compares only the string form of archive entry names against the extraction root, failing to prevent symbolic link traversal. The extraction functions (extractAllTo, extractAllToAsync, extractEntryTo) open destination files with fs.openSync without using O_NOFOLLOW or pre-write lstat checks, allowing writes through symbolic links pointing outside the extraction root. This enables an attacker who can create symbolic links in the extraction directory to overwrite arbitrary files that the extracting process can write to, provided overwrite is enabled.
Potential Impact
An attacker able to create symbolic links in a shared, reused, or predictable extraction directory can cause the extraction process to overwrite arbitrary files outside the intended extraction root. This can lead to unauthorized file modification or replacement, potentially compromising system integrity or security. The attack requires local write permissions to the extraction directory and the ability to enable overwrite during extraction.
Mitigation Recommendations
No explicit patch or fix is stated in the provided data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid extracting untrusted archives in shared or predictable directories where symbolic links can be created. Disable overwrite during extraction if possible and validate extraction paths with proper symbolic link resolution checks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-19T20:34:19.724Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8c45b3acd9273b4994634b
Added to database: 08/24/2026, 13:22:59 UTC
Last enriched: 09/10/2026, 21:47:46 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 71
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.