CyberRota Analysis
AI-GeneratedThe adm-zip library in JavaScript, used for handling ZIP archives, is vulnerable to privilege escalation due to improper handling of Unix permission bits, allowing an attacker to create a ZIP file that, when extracted with root privileges, can result in a setuid binary. This vulnerability poses a significant risk in environments like Docker builds and CI/CD pipelines, where extraction often occurs with elevated permissions. Organizations utilizing affected versions of adm-zip should prioritize upgrading to version 0.6.1 or later to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode `04755`. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution. Version 0.6.1 fixes the issue.