{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/adm-zip--0.6.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:adm-zip_project:adm-zip:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"id":"CVE-2026-102282"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=23482FFE-B5C9-5736-A66B-ABBDCFF4AFA5\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["adm-zip (\u003c= 0.6.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","nodejs","supply-chain"],"_cs_type":"advisory","_cs_vendors":["cthackers"],"content_html":"\u003cp\u003eThe adm-zip library for Node.js (version \u0026lt;= 0.6.0) contains a critical flaw in how it handles file permissions during archive extraction. When the \u003ccode\u003ekeepOriginalPermission=true\u003c/code\u003e flag is used with \u003ccode\u003eextractAllTo()\u003c/code\u003e or \u003ccode\u003eextractEntryTo()\u003c/code\u003e, the library reads Unix permission bits directly from the ZIP file headers and applies them to the filesystem using \u003ccode\u003efs.chmodSync()\u003c/code\u003e. Critically, the library fails to sanitize these bits, preserving the SUID (set-user-ID), SGID (set-group-ID), and sticky bits (mask 0o7777).\u003c/p\u003e\n\u003cp\u003eIf an archive is processed by a privileged user (such as a root-level build pipeline, Docker build, or administrative installer), an attacker can craft a ZIP file containing an entry with SUID bits set. Upon extraction, the resulting file will be owned by root with the SUID bit enabled. If this file is later accessible and executed by a lesser-privileged user, the attacker's code will run with elevated (root) privileges. This behavior represents a form of local privilege escalation facilitated by insecure archive processing.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious ZIP archive where an entry's \u003ccode\u003eexternal_attr\u003c/code\u003e is set to include the SUID bit (e.g., \u003ccode\u003e04755\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe attacker delivers the archive to the target system (e.g., via upload endpoint, malicious build dependency, or project artifact).\u003c/li\u003e\n\u003cli\u003eThe victim application or automated build system invokes \u003ccode\u003eadm-zip\u003c/code\u003e with \u003ccode\u003ekeepOriginalPermission=true\u003c/code\u003e to extract the archive.\u003c/li\u003e\n\u003cli\u003eThe extraction process, running with root privileges, calls \u003ccode\u003efs.chmodSync()\u003c/code\u003e using the attacker-controlled mode bits.\u003c/li\u003e\n\u003cli\u003eThe library writes the file to the filesystem, resulting in a root-owned file with the SUID bit set.\u003c/li\u003e\n\u003cli\u003eThe SUID binary is moved or preserved through deployment artifacts (e.g., via \u003ccode\u003ecp -a\u003c/code\u003e or \u003ccode\u003ersync\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAn unprivileged user or service account executes the malicious binary.\u003c/li\u003e\n\u003cli\u003eThe binary executes with root privileges, successfully achieving local privilege escalation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full local privilege escalation on systems where the library is used to handle untrusted archives under high-privilege execution contexts (e.g., root). This is particularly relevant in CI/CD pipelines and automated deployment workflows. The vulnerability is tracked as CVE-2026-102282.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003eadm-zip\u003c/code\u003e dependency to a version where this permission bit filtering issue is remediated (note: if a patch is not yet available, avoid using the \u003ccode\u003ekeepOriginalPermission\u003c/code\u003e flag when extracting untrusted ZIP archives).\u003c/li\u003e\n\u003cli\u003eAudit CI/CD pipelines and deployment scripts that use \u003ccode\u003eadm-zip\u003c/code\u003e to ensure that extraction does not occur under root privileges, or that source archives are verified via cryptographic signatures before extraction.\u003c/li\u003e\n\u003cli\u003eUse static analysis or custom instrumentation to identify code paths where \u003ccode\u003eadm-zip\u003c/code\u003e is invoked with \u003ccode\u003ekeepOriginalPermission=true\u003c/code\u003e on externally sourced data.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-03T00:53:58Z","date_published":"2026-09-29T22:18:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-adm-zip-suid-pe/","summary":"The adm-zip Node.js library fails to filter SUID/SGID bits when extracting ZIP archives with 'keepOriginalPermission' enabled, allowing for root-level privilege escalation when archives are extracted by privileged processes.","title":"Local Privilege Escalation in adm-zip via Unsafe Extraction of SUID/SGID Bits","url":"https://feed.craftedsignal.io/briefs/2026-09-adm-zip-suid-pe/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:adm-zip_project:adm-zip:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-39244"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["adm-zip (\u003c= 0.6.0)"],"_cs_severities":["low"],"_cs_tags":["library","vulnerability","denial-of-service"],"_cs_type":"advisory","_cs_vendors":["adm-zip"],"content_html":"\u003cp\u003eThe adm-zip library for Node.js (version 0.6.0 and earlier) contains a security flaw in its decompression-bomb protection mechanism, which was intended to mitigate CVE-2026-39244. The vulnerability exists within \u003ccode\u003emethods/inflater.js\u003c/code\u003e, where a conditional check applies a \u003ccode\u003emaxOutputLength\u003c/code\u003e constraint to \u003ccode\u003ezlib.inflateRawSync\u003c/code\u003e only if the declared uncompressed size of the ZIP entry is greater than zero.\u003c/p\u003e\n\u003cp\u003eAn attacker can bypass this protection by crafting a malicious ZIP archive where the declared uncompressed size field in the local file header and central directory is set to exactly 0. Because the condition \u003ccode\u003eexpectedLength \u0026gt; 0\u003c/code\u003e fails, the \u003ccode\u003emaxOutputLength\u003c/code\u003e option is omitted, causing the library to default to zlib's internal limits rather than the intended application-level cap. This allows a small, highly compressed payload to expand into a significantly larger buffer in memory, leading to potential denial-of-service via OOM (Out-of-Memory) conditions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker generates a highly redundant file to achieve high compression ratios (e.g., repeating bytes).\u003c/li\u003e\n\u003cli\u003eAttacker compresses this file using the DEFLATE algorithm.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the ZIP archive structure to set both the local file header and central directory 'uncompressed size' fields to 0.\u003c/li\u003e\n\u003cli\u003eAttacker delivers the malicious ZIP archive to a target application using adm-zip.\u003c/li\u003e\n\u003cli\u003eThe target application passes the untrusted ZIP to \u003ccode\u003enew AdmZip(buffer)\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application calls \u003ccode\u003e.getData()\u003c/code\u003e, \u003ccode\u003e.readFile()\u003c/code\u003e, or similar extraction methods on the malicious entry.\u003c/li\u003e\n\u003cli\u003eThe adm-zip library ignores the \u003ccode\u003emaxOutputLength\u003c/code\u003e constraint due to the 0-value size field.\u003c/li\u003e\n\u003cli\u003eZlib decompresses the full payload into memory, resulting in excessive resource consumption and potential process termination.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects any application using adm-zip to process untrusted archives, such as web upload handlers, CI/CD artifact extractors, or email gateway scanners. Successful exploitation can lead to process crashes and denial-of-service by consuming disproportionate amounts of server memory, bypassing the intended safety guards implemented against decompression bombs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003eadm-zip\u003c/code\u003e package to a version that implements unconditional \u003ccode\u003emaxOutputLength\u003c/code\u003e enforcement or adds an independent compression-ratio verification mechanism.\u003c/li\u003e\n\u003cli\u003eUntil an upgrade is available, implement a wrapper around \u003ccode\u003eadm-zip\u003c/code\u003e functions that validates the actual size of the output buffer against a strict absolute ceiling before returning it to the application logic.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual memory spikes or process crashes associated with ZIP processing modules.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T22:18:15Z","date_published":"2026-09-29T22:18:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-adm-zip-bypass/","summary":"The adm-zip Node.js library fails to enforce memory limits during decompression when the ZIP entry uncompressed size header is set to zero, enabling potential memory exhaustion attacks.","title":"adm-zip Decompression Bomb Protection Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-adm-zip-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Adm-Zip (\u003c= 0.6.0)","version":"https://jsonfeed.org/version/1.1"}