{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/cthackers/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:adm-zip_project:adm-zip:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"id":"CVE-2026-102282"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=23482FFE-B5C9-5736-A66B-ABBDCFF4AFA5\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["adm-zip (\u003c= 0.6.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","nodejs","supply-chain"],"_cs_type":"advisory","_cs_vendors":["cthackers"],"content_html":"\u003cp\u003eThe adm-zip library for Node.js (version \u0026lt;= 0.6.0) contains a critical flaw in how it handles file permissions during archive extraction. When the \u003ccode\u003ekeepOriginalPermission=true\u003c/code\u003e flag is used with \u003ccode\u003eextractAllTo()\u003c/code\u003e or \u003ccode\u003eextractEntryTo()\u003c/code\u003e, the library reads Unix permission bits directly from the ZIP file headers and applies them to the filesystem using \u003ccode\u003efs.chmodSync()\u003c/code\u003e. Critically, the library fails to sanitize these bits, preserving the SUID (set-user-ID), SGID (set-group-ID), and sticky bits (mask 0o7777).\u003c/p\u003e\n\u003cp\u003eIf an archive is processed by a privileged user (such as a root-level build pipeline, Docker build, or administrative installer), an attacker can craft a ZIP file containing an entry with SUID bits set. Upon extraction, the resulting file will be owned by root with the SUID bit enabled. If this file is later accessible and executed by a lesser-privileged user, the attacker's code will run with elevated (root) privileges. This behavior represents a form of local privilege escalation facilitated by insecure archive processing.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious ZIP archive where an entry's \u003ccode\u003eexternal_attr\u003c/code\u003e is set to include the SUID bit (e.g., \u003ccode\u003e04755\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe attacker delivers the archive to the target system (e.g., via upload endpoint, malicious build dependency, or project artifact).\u003c/li\u003e\n\u003cli\u003eThe victim application or automated build system invokes \u003ccode\u003eadm-zip\u003c/code\u003e with \u003ccode\u003ekeepOriginalPermission=true\u003c/code\u003e to extract the archive.\u003c/li\u003e\n\u003cli\u003eThe extraction process, running with root privileges, calls \u003ccode\u003efs.chmodSync()\u003c/code\u003e using the attacker-controlled mode bits.\u003c/li\u003e\n\u003cli\u003eThe library writes the file to the filesystem, resulting in a root-owned file with the SUID bit set.\u003c/li\u003e\n\u003cli\u003eThe SUID binary is moved or preserved through deployment artifacts (e.g., via \u003ccode\u003ecp -a\u003c/code\u003e or \u003ccode\u003ersync\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAn unprivileged user or service account executes the malicious binary.\u003c/li\u003e\n\u003cli\u003eThe binary executes with root privileges, successfully achieving local privilege escalation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full local privilege escalation on systems where the library is used to handle untrusted archives under high-privilege execution contexts (e.g., root). This is particularly relevant in CI/CD pipelines and automated deployment workflows. The vulnerability is tracked as CVE-2026-102282.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003eadm-zip\u003c/code\u003e dependency to a version where this permission bit filtering issue is remediated (note: if a patch is not yet available, avoid using the \u003ccode\u003ekeepOriginalPermission\u003c/code\u003e flag when extracting untrusted ZIP archives).\u003c/li\u003e\n\u003cli\u003eAudit CI/CD pipelines and deployment scripts that use \u003ccode\u003eadm-zip\u003c/code\u003e to ensure that extraction does not occur under root privileges, or that source archives are verified via cryptographic signatures before extraction.\u003c/li\u003e\n\u003cli\u003eUse static analysis or custom instrumentation to identify code paths where \u003ccode\u003eadm-zip\u003c/code\u003e is invoked with \u003ccode\u003ekeepOriginalPermission=true\u003c/code\u003e on externally sourced data.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-03T00:53:58Z","date_published":"2026-09-29T22:18:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-adm-zip-suid-pe/","summary":"The adm-zip Node.js library fails to filter SUID/SGID bits when extracting ZIP archives with 'keepOriginalPermission' enabled, allowing for root-level privilege escalation when archives are extracted by privileged processes.","title":"Local Privilege Escalation in adm-zip via Unsafe Extraction of SUID/SGID Bits","url":"https://feed.craftedsignal.io/briefs/2026-09-adm-zip-suid-pe/"}],"language":"en","title":"CraftedSignal Threat Feed - Cthackers","version":"https://jsonfeed.org/version/1.1"}