<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:adm-Zip_project:adm-Zip:*:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aadm-zip_projectadm-zipnode.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:18:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aadm-zip_projectadm-zipnode.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation in adm-zip via Unsafe Extraction of SUID/SGID Bits</title><link>https://feed.craftedsignal.io/briefs/2026-09-adm-zip-suid-pe/</link><pubDate>Tue, 29 Sep 2026 22:18:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-adm-zip-suid-pe/</guid><description>The adm-zip Node.js library fails to filter SUID/SGID bits when extracting ZIP archives with 'keepOriginalPermission' enabled, allowing for root-level privilege escalation when archives are extracted by privileged processes.</description><content:encoded><![CDATA[<p>The adm-zip library for Node.js (version &lt;= 0.6.0) contains a critical flaw in how it handles file permissions during archive extraction. When the <code>keepOriginalPermission=true</code> flag is used with <code>extractAllTo()</code> or <code>extractEntryTo()</code>, the library reads Unix permission bits directly from the ZIP file headers and applies them to the filesystem using <code>fs.chmodSync()</code>. Critically, the library fails to sanitize these bits, preserving the SUID (set-user-ID), SGID (set-group-ID), and sticky bits (mask 0o7777).</p>
<p>If an archive is processed by a privileged user (such as a root-level build pipeline, Docker build, or administrative installer), an attacker can craft a ZIP file containing an entry with SUID bits set. Upon extraction, the resulting file will be owned by root with the SUID bit enabled. If this file is later accessible and executed by a lesser-privileged user, the attacker's code will run with elevated (root) privileges. This behavior represents a form of local privilege escalation facilitated by insecure archive processing.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious ZIP archive where an entry's <code>external_attr</code> is set to include the SUID bit (e.g., <code>04755</code>).</li>
<li>The attacker delivers the archive to the target system (e.g., via upload endpoint, malicious build dependency, or project artifact).</li>
<li>The victim application or automated build system invokes <code>adm-zip</code> with <code>keepOriginalPermission=true</code> to extract the archive.</li>
<li>The extraction process, running with root privileges, calls <code>fs.chmodSync()</code> using the attacker-controlled mode bits.</li>
<li>The library writes the file to the filesystem, resulting in a root-owned file with the SUID bit set.</li>
<li>The SUID binary is moved or preserved through deployment artifacts (e.g., via <code>cp -a</code> or <code>rsync</code>).</li>
<li>An unprivileged user or service account executes the malicious binary.</li>
<li>The binary executes with root privileges, successfully achieving local privilege escalation.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to full local privilege escalation on systems where the library is used to handle untrusted archives under high-privilege execution contexts (e.g., root). This is particularly relevant in CI/CD pipelines and automated deployment workflows. The vulnerability is tracked as CVE-2026-102282.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the <code>adm-zip</code> dependency to a version where this permission bit filtering issue is remediated (note: if a patch is not yet available, avoid using the <code>keepOriginalPermission</code> flag when extracting untrusted ZIP archives).</li>
<li>Audit CI/CD pipelines and deployment scripts that use <code>adm-zip</code> to ensure that extraction does not occur under root privileges, or that source archives are verified via cryptographic signatures before extraction.</li>
<li>Use static analysis or custom instrumentation to identify code paths where <code>adm-zip</code> is invoked with <code>keepOriginalPermission=true</code> on externally sourced data.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>nodejs</category><category>supply-chain</category></item><item><title>adm-zip Decompression Bomb Protection Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-09-adm-zip-bypass/</link><pubDate>Tue, 29 Sep 2026 22:18:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-adm-zip-bypass/</guid><description>The adm-zip Node.js library fails to enforce memory limits during decompression when the ZIP entry uncompressed size header is set to zero, enabling potential memory exhaustion attacks.</description><content:encoded><![CDATA[<p>The adm-zip library for Node.js (version 0.6.0 and earlier) contains a security flaw in its decompression-bomb protection mechanism, which was intended to mitigate CVE-2026-39244. The vulnerability exists within <code>methods/inflater.js</code>, where a conditional check applies a <code>maxOutputLength</code> constraint to <code>zlib.inflateRawSync</code> only if the declared uncompressed size of the ZIP entry is greater than zero.</p>
<p>An attacker can bypass this protection by crafting a malicious ZIP archive where the declared uncompressed size field in the local file header and central directory is set to exactly 0. Because the condition <code>expectedLength &gt; 0</code> fails, the <code>maxOutputLength</code> option is omitted, causing the library to default to zlib's internal limits rather than the intended application-level cap. This allows a small, highly compressed payload to expand into a significantly larger buffer in memory, leading to potential denial-of-service via OOM (Out-of-Memory) conditions.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker generates a highly redundant file to achieve high compression ratios (e.g., repeating bytes).</li>
<li>Attacker compresses this file using the DEFLATE algorithm.</li>
<li>Attacker modifies the ZIP archive structure to set both the local file header and central directory 'uncompressed size' fields to 0.</li>
<li>Attacker delivers the malicious ZIP archive to a target application using adm-zip.</li>
<li>The target application passes the untrusted ZIP to <code>new AdmZip(buffer)</code>.</li>
<li>The application calls <code>.getData()</code>, <code>.readFile()</code>, or similar extraction methods on the malicious entry.</li>
<li>The adm-zip library ignores the <code>maxOutputLength</code> constraint due to the 0-value size field.</li>
<li>Zlib decompresses the full payload into memory, resulting in excessive resource consumption and potential process termination.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects any application using adm-zip to process untrusted archives, such as web upload handlers, CI/CD artifact extractors, or email gateway scanners. Successful exploitation can lead to process crashes and denial-of-service by consuming disproportionate amounts of server memory, bypassing the intended safety guards implemented against decompression bombs.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>adm-zip</code> package to a version that implements unconditional <code>maxOutputLength</code> enforcement or adds an independent compression-ratio verification mechanism.</li>
<li>Until an upgrade is available, implement a wrapper around <code>adm-zip</code> functions that validates the actual size of the output buffer against a strict absolute ceiling before returning it to the application logic.</li>
<li>Monitor logs for unusual memory spikes or process crashes associated with ZIP processing modules.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>library</category><category>vulnerability</category><category>denial-of-service</category></item></channel></rss>