Local Privilege Escalation in adm-zip via Unsafe Extraction of SUID/SGID Bits
The adm-zip Node.js library fails to filter SUID/SGID bits when extracting ZIP archives with 'keepOriginalPermission' enabled, allowing for root-level privilege escalation when archives are extracted by privileged processes.
CVE search metadata
CVE search record: CVE-2026-102282. KEV: no. Product: adm-zip (<= 0.6.0). Brief: Local Privilege Escalation in adm-zip via Unsafe Extraction of SUID/SGID Bits. Brief link: https://feed.craftedsignal.io/briefs/2026-09-adm-zip-suid-pe/
What's new
- 1. poc_available; added CVE-2026-102282 Oct 3, 00:53 via sploitus
The adm-zip library for Node.js (version <= 0.6.0) contains a critical flaw in how it handles file permissions during archive extraction. When the keepOriginalPermission=true flag is used with extractAllTo() or extractEntryTo(), the library reads Unix permission bits directly from the ZIP file headers and applies them to the filesystem using fs.chmodSync(). Critically, the library fails to sanitize these bits, preserving the SUID (set-user-ID), SGID (set-group-ID), and sticky bits (mask 0o7777).
If an archive is processed by a privileged user (such as a root-level build pipeline, Docker build, or administrative installer), an attacker can craft a ZIP file containing an entry with SUID bits set. Upon extraction, the resulting file will be owned by root with the SUID bit enabled. If this file is later accessible and executed by a lesser-privileged user, the attacker's code will run with elevated (root) privileges. This behavior represents a form of local privilege escalation facilitated by insecure archive processing.
Attack Chain
- Attacker crafts a malicious ZIP archive where an entry's
external_attris set to include the SUID bit (e.g.,04755). - The attacker delivers the archive to the target system (e.g., via upload endpoint, malicious build dependency, or project artifact).
- The victim application or automated build system invokes
adm-zipwithkeepOriginalPermission=trueto extract the archive. - The extraction process, running with root privileges, calls
fs.chmodSync()using the attacker-controlled mode bits. - The library writes the file to the filesystem, resulting in a root-owned file with the SUID bit set.
- The SUID binary is moved or preserved through deployment artifacts (e.g., via
cp -aorrsync). - An unprivileged user or service account executes the malicious binary.
- The binary executes with root privileges, successfully achieving local privilege escalation.
Impact
Successful exploitation leads to full local privilege escalation on systems where the library is used to handle untrusted archives under high-privilege execution contexts (e.g., root). This is particularly relevant in CI/CD pipelines and automated deployment workflows. The vulnerability is tracked as CVE-2026-102282.
Recommendation
- Upgrade the
adm-zipdependency to a version where this permission bit filtering issue is remediated (note: if a patch is not yet available, avoid using thekeepOriginalPermissionflag when extracting untrusted ZIP archives). - Audit CI/CD pipelines and deployment scripts that use
adm-zipto ensure that extraction does not occur under root privileges, or that source archives are verified via cryptographic signatures before extraction. - Use static analysis or custom instrumentation to identify code paths where
adm-zipis invoked withkeepOriginalPermission=trueon externally sourced data.
Immediate actions
Audit codebase for usage of adm-zip library with keepOriginalPermission=true flag
Mitigations
Remove keepOriginalPermission=true from extraction logic until an updated package version is available
CVE-2026-102282