<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cthackers - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/cthackers/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:18:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/cthackers/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation in adm-zip via Unsafe Extraction of SUID/SGID Bits</title><link>https://feed.craftedsignal.io/briefs/2026-09-adm-zip-suid-pe/</link><pubDate>Tue, 29 Sep 2026 22:18:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-adm-zip-suid-pe/</guid><description>The adm-zip Node.js library fails to filter SUID/SGID bits when extracting ZIP archives with 'keepOriginalPermission' enabled, allowing for root-level privilege escalation when archives are extracted by privileged processes.</description><content:encoded><![CDATA[<p>The adm-zip library for Node.js (version &lt;= 0.6.0) contains a critical flaw in how it handles file permissions during archive extraction. When the <code>keepOriginalPermission=true</code> flag is used with <code>extractAllTo()</code> or <code>extractEntryTo()</code>, the library reads Unix permission bits directly from the ZIP file headers and applies them to the filesystem using <code>fs.chmodSync()</code>. Critically, the library fails to sanitize these bits, preserving the SUID (set-user-ID), SGID (set-group-ID), and sticky bits (mask 0o7777).</p>
<p>If an archive is processed by a privileged user (such as a root-level build pipeline, Docker build, or administrative installer), an attacker can craft a ZIP file containing an entry with SUID bits set. Upon extraction, the resulting file will be owned by root with the SUID bit enabled. If this file is later accessible and executed by a lesser-privileged user, the attacker's code will run with elevated (root) privileges. This behavior represents a form of local privilege escalation facilitated by insecure archive processing.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious ZIP archive where an entry's <code>external_attr</code> is set to include the SUID bit (e.g., <code>04755</code>).</li>
<li>The attacker delivers the archive to the target system (e.g., via upload endpoint, malicious build dependency, or project artifact).</li>
<li>The victim application or automated build system invokes <code>adm-zip</code> with <code>keepOriginalPermission=true</code> to extract the archive.</li>
<li>The extraction process, running with root privileges, calls <code>fs.chmodSync()</code> using the attacker-controlled mode bits.</li>
<li>The library writes the file to the filesystem, resulting in a root-owned file with the SUID bit set.</li>
<li>The SUID binary is moved or preserved through deployment artifacts (e.g., via <code>cp -a</code> or <code>rsync</code>).</li>
<li>An unprivileged user or service account executes the malicious binary.</li>
<li>The binary executes with root privileges, successfully achieving local privilege escalation.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to full local privilege escalation on systems where the library is used to handle untrusted archives under high-privilege execution contexts (e.g., root). This is particularly relevant in CI/CD pipelines and automated deployment workflows. The vulnerability is tracked as CVE-2026-102282.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the <code>adm-zip</code> dependency to a version where this permission bit filtering issue is remediated (note: if a patch is not yet available, avoid using the <code>keepOriginalPermission</code> flag when extracting untrusted ZIP archives).</li>
<li>Audit CI/CD pipelines and deployment scripts that use <code>adm-zip</code> to ensure that extraction does not occur under root privileges, or that source archives are verified via cryptographic signatures before extraction.</li>
<li>Use static analysis or custom instrumentation to identify code paths where <code>adm-zip</code> is invoked with <code>keepOriginalPermission=true</code> on externally sourced data.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>nodejs</category><category>supply-chain</category></item></channel></rss>