{"id":"GHSA-p634-w6r4-rjp2","title":"adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content","summary":"adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content","severity":"medium","cvss":5.9,"cwe":["CWE-436","CWE-696"],"vendor":"adm-zip","product":"adm-zip","ecosystem":"npm","affected":["adm-zip <= 0.6.0"],"patched":["adm-zip 0.6.1"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T23:11:04Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-p634-w6r4-rjp2","references":[{"url":"https://github.com/cthackers/adm-zip/security/advisories/GHSA-p634-w6r4-rjp2"},{"url":"https://github.com/cthackers/adm-zip/commit/05101d47b3b983b705cc3e66fc34366118ba7b99"},{"url":"https://github.com/cthackers/adm-zip/releases/tag/v0.6.1"},{"url":"https://github.com/advisories/GHSA-p634-w6r4-rjp2"}],"tags":["ghsa","npm"],"ingestedAt":"2026-09-29T23:52:50.541Z","slug":"GHSA-p634-w6r4-rjp2","body":"## Overview\n\n### Summary\n\nA ZIP file can contain two entries with the identical name. adm-zip keeps both in its internal entry list, but its name-lookup table only retains the last one written. `getEntry(name)` and `extractAllTo()` walk these two different internal structures, so they can each resolve a duplicate name to a *different* entry. An application that validates a named entry's contents via `getEntry()` before trusting an archive, then extracts the whole archive, can end up approving one file's content while a different file's bytes are what actually land on disk under that name.\n\n### Details\n- `zipFile.js:58-83` retains both entries in `entryList` but overwrites `entryTable[name]` with only the last one written.\n- `adm-zip.js:83-95,658-663` uses `entryTable` for `getEntry()` lookups — returns the *last* duplicate.\n- `adm-zip.js:769-914` iterates `entryList` for extraction — writes the *first* duplicate (sync, default overwrite policy).\n\n\n### PoC\n```js\nconst AdmZip = require('adm-zip');\nconst z = new AdmZip({ noSort: true });\nz.addFile('a.txt', Buffer.from('FIRST'));\nz.addFile('b.txt', Buffer.from('SECOND'));\nconst raw = Buffer.from(z.toBuffer());\n// rename the a.txt entry to b.txt directly in the raw bytes\nfor (let at = raw.indexOf('a.txt'); at >= 0; at = raw.indexOf('a.txt', at + 5)) {\n  raw.write('b.txt', at);\n}\nconst parsed = new AdmZip(raw, { noSort: true });\nconst validated = parsed.getEntry('b.txt').getData().toString();\nparsed.extractAllTo(outDir, false);\n// validated === \"SECOND\", but the file written to disk === \"FIRST\"\n```\n\nReproduced on the pinned commit (`2b4d84087d45344643e0183756e19191d52815cc`)\n\n### Impact\nAn application that checks a named entry's content before trusting an untrusted ZIP, then extracts it, can be made to approve different bytes than what actually gets written to disk — the classic check/use split that this kind of validate-then-extract pattern relies on.\n\n## Affected packages\n\n- `adm-zip <= 0.6.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `adm-zip 0.6.1`","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}