CPE
high
advisory
Local Privilege Escalation in adm-zip via Unsafe Extraction of SUID/SGID Bits
1 TTP 1 CVEThe adm-zip Node.js library fails to filter SUID/SGID bits when extracting ZIP archives with 'keepOriginalPermission' enabled, allowing for root-level privilege escalation when archives are extracted by privileged processes.
PoC
adm-zip
privilege-escalation
nodejs
supply-chain
1t
1c
updated
low
advisory
adm-zip Decompression Bomb Protection Bypass
1 CVEThe adm-zip Node.js library fails to enforce memory limits during decompression when the ZIP entry uncompressed size header is set to zero, enabling potential memory exhaustion attacks.
adm-zip
library
vulnerability
denial-of-service
1c