adm-zip has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.0 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.0
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
adm-zip vulnerabilities
CVEs affecting adm-zip, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-77301High· 7.5PoCadm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js
adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value …
▾ Midnightadm-zip · adm-zipEPSS 0.41%via NVD
CVE-2026-76845Medium· 6.5adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite
adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite
▾ Sunlitadm-zip · adm-zipEPSS 0.13%via GHSA