GHSA-p634-w6r4-rjp2Medium· 5.9▾ Sunlitadm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A ZIP file can contain two entries with the identical name. adm-zip keeps both in its internal entry list, but its name-lookup table only retains the last one written. getEntry(name) and extractAllTo() walk these two different internal structures, so they can each resolve a duplicate name to a different entry. An application that validates a named entry's contents via getEntry() before trusting an archive, then extracts the whole archive, can end up approving one file's content while a different file's bytes are what actually land on disk under that name.
zipFile.js:58-83 retains both entries in entryList but overwrites entryTable[name] with only the last one written.adm-zip.js:83-95,658-663 uses entryTable for getEntry() lookups — returns the last duplicate.adm-zip.js:769-914 iterates entryList for extraction — writes the first duplicate (sync, default overwrite policy).const AdmZip = require('adm-zip');
const z = new AdmZip({ noSort: true });
z.addFile('a.txt', Buffer.from('FIRST'));
z.addFile('b.txt', Buffer.from('SECOND'));
const raw = Buffer.from(z.toBuffer());
// rename the a.txt entry to b.txt directly in the raw bytes
for (let at = raw.indexOf('a.txt'); at >= 0; at = raw.indexOf('a.txt', at + 5)) {
raw.write('b.txt', at);
}
const parsed = new AdmZip(raw, { noSort: true });
const validated = parsed.getEntry('b.txt').getData().toString();
parsed.extractAllTo(outDir, false);
// validated === "SECOND", but the file written to disk === "FIRST"
Reproduced on the pinned commit (2b4d84087d45344643e0183756e19191d52815cc)
An application that checks a named entry's content before trusting an untrusted ZIP, then extracts it, can be made to approve different bytes than what actually gets written to disk — the classic check/use split that this kind of validate-then-extract pattern relies on.
adm-zip <= 0.6.0Upgrade to a patched release:
adm-zip 0.6.1Connected by shared product, vendor, weakness, or advisory.
GHSA-c6fg-446q-cg94Medium· 5.3adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path
GHSA-8238-w5pm-2374High· 7.5adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
CVE-2026-102282High· 7.1adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
GHSA-rcw4-f5rp-g42vHigh· 7.5adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
CVE-2026-77301High· 7.5adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js
CVE-2026-76845Medium· 6.5adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination