CVE-2026-102282 with a CVSS score of 7.1 is a CWE-732 vulnerability in adm-zip that lets attackers preserve SUID/SGID bits from untrusted ZIPs, resulting in local privilege escalation when extraction runs as root. Affected versions include <= 0.6.0. The flaw occurs due to the tool applying Unix permission bits directly from a zip entry without filtering bits. An attacker can craft a zip with a setuid binary that preserves its mode, leading to a root-owned setuid file being executed later by an unprivileged user. This vulnerability impacts applications and pipelines extracting untrusted archives while running as root, but default-usage deployments are not affected.
We recommend you to update adm-zip to version 0.6.1.[/subscribe_to_unlock_form]
CVE-2026-102282 with a CVSS score of 7.1 is a CWE-732 vulnerability in adm-zip that lets attackers preserve SUID/SGID bits from untrusted ZIPs, resulting in local privilege escalation when extraction runs as root. Affected versions include <= 0.6.0. The flaw occurs due to the tool applying Unix permission bits directly from a zip entry without filtering bits. An attacker can craft a zip with a setuid binary that preserves its mode, leading to a root-owned setuid file being executed later by an unprivileged user. This vulnerability impacts applications and pipelines extracting untrusted archives while running as root, but default-usage deployments are not affected.
We recommend you to update adm-zip to version 0.6.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]