Repository navigation
chore(deps): update dependency adm-zip to v0.6.1 [security] - #9753
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
requested review from
arjita-mitra,
e-maad,
otto-the-bot,
screendriver,
thisisamir98 and
zskhan
as code owners
September 19, 2026 17:33
renovate
Bot
force-pushed
the
renovate/npm-adm-zip-vulnerability
branch
from
September 24, 2026 11:37
bb5197a to
f075a0b
Compare
renovate
Bot
force-pushed
the
renovate/npm-adm-zip-vulnerability
branch
from
October 5, 2026 17:30
f075a0b to
a76287f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.6.0→0.6.1Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
CVE-2026-77301 / GHSA-7q85-xj36-vmfc
More information
Details
Summary
adm-zip allocates an entry's output buffer from the declared uncompressed size (central-directory
sizefield) before validating it against the actual data. A tiny crafted ZIP that declares a huge uncompressed size forces a multi-gigabyte allocation from a few bytes.Impact
On adm-zip 0.5.17 (latest), Node 24, a 105-byte ZIP with one stored entry declaring size = 1,774,399,200 makes
new AdmZip(buf).getEntries()[0].getData()commit ~1.8 GB of resident memory in ~4.4 s before throwingError: ADM-ZIP: CRC32 checksum failed, roughly 16 million times the input size. Because the buffer is committed before any validation, on a memory-constrained host (containers, serverless, small VMs) the allocation OOM-kills the process before the CRC check (uncatchable), and concurrent requests can exhaust memory even on larger hosts. Any service that reads entries from untrusted ZIPs is exposed to a remote denial of service.Steps to reproduce
Attachments are not supported in the advisory form, so the 105-byte PoC (sha256
980d34356fbb248fe527b9d0ac3eabc5c99393a374014be6199523de16709386) is inlined as base64 in this self-contained reproducer:The single entry declares uncompressed size = 1,774,399,200 with a compressed size of 5.
getData()allocates the full declared size before the CRC check runs, so the memory is committed regardless of the (tiny) actual payload.Root cause
zipEntry.jsdoesBuffer.alloc(<declared uncompressed size>)before checking the declared size against the compressed size / available bytes.Suggested fix
Validate the declared uncompressed size against the compressed size and a configurable maximum before allocating (yauzl, for example, requires the caller to bound this); reject or stream when the declared size is implausible relative to the input. Happy to send a patch.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
CVE-2026-102282 / GHSA-j5f4-cc29-5x44
More information
Details
Summary
adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via
fs.chmodSync()whenkeepOriginalPermission=trueis passed toextractAllTo()/extractEntryTo()— and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extracted binary with mode04755. When extraction runs as root (the default posture in Docker builds, CI runners, and privileged install steps — the exact environments where this flag is used), the resulting root-owned setuid file is executed later by a lesser-privileged user, turning the attacker's code into a root execution.Details
The mode a zip entry wants is read back from the external file attributes in the header, and the mask used keeps every special bit:
0xfffis0o7777— it preserves setuid (0o4000), setgid (0o2000) and the sticky bit (0o1000) along with the rwx bits. Shifting by 16 is the standard Unix convention for where zip stores the mode; the mask is the problem.When the flag is on, that value goes straight to the write:
No
& 0o777, no stripping of0o7000. Attacker-controlled bytes in the zip decide the final mode of a file the library creates on disk. Directory entries are affected too (adm-zip.js:855), so a setgid bit on a directory entry also carries over and gives new files inside it group inheritance.PoC
Tested against adm-zip@0.6.0 (latest as of 2026-08-01), Node 22, Linux.
realistic attacker path — no adm-zip APIs involved in creating it):
keepOriginalPermission=false):mode comes out
0666, no setuid. The flag is the enabler.Alternative supply path, if the zip is built in-process with adm-zip's own API:
Impact
Privilege escalation.
The vulnerability class is CWE-732 (incorrect permission assignment): permission bits taken from untrusted input are applied with no filtering.
Realistic chain:
keepOriginalPermission=true. Docker builds run as root by default and CI/install steps commonly do too; this flag is specifically the tooling used in permission-preserving deploy flows.cp -a/rsync mode-bit propagation, into the runtime environment.Who is impacted: applications and pipelines that extract untrusted archives with
keepOriginalPermission=truewhile running as root.Default-usage deployments (flag off) are not affected; non-root extraction results in a harmless self-owned setuid file.
Severity: Medium
Suggested fix, one line in the getter:
Severity
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
GHSA-p634-w6r4-rjp2
More information
Details
Summary
A ZIP file can contain two entries with the identical name. adm-zip keeps both in its internal entry list, but its name-lookup table only retains the last one written.
getEntry(name)andextractAllTo()walk these two different internal structures, so they can each resolve a duplicate name to a different entry. An application that validates a named entry's contents viagetEntry()before trusting an archive, then extracts the whole archive, can end up approving one file's content while a different file's bytes are what actually land on disk under that name.Details
zipFile.js:58-83retains both entries inentryListbut overwritesentryTable[name]with only the last one written.adm-zip.js:83-95,658-663usesentryTableforgetEntry()lookups — returns the last duplicate.adm-zip.js:769-914iteratesentryListfor extraction — writes the first duplicate (sync, default overwrite policy).PoC
Reproduced on the pinned commit (
2b4d84087d45344643e0183756e19191d52815cc)Impact
An application that checks a named entry's content before trusting an untrusted ZIP, then extracts it, can be made to approve different bytes than what actually gets written to disk — the classic check/use split that this kind of validate-then-extract pattern relies on.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
cthackers/adm-zip (adm-zip)
v0.6.1Compare Source
Full Changelog: cthackers/adm-zip@v0.6.0...v0.6.1
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.