adm-zip
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting adm-zippage 1 of 1
- CVE-2018-1002204MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.4.112018-07-25
adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known a…
- CVE-2026-39244HIGHCVSS 7.5EG 7.5✓ Fixed in 0.6.02026-07-10
adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js line 103, Buffer.alloc(_centralHeader.size) allocates memory based on the declared uncompress…
- CVE-2026-76845MEDIUMCVSS 6.5EG 6.52026-08-24
adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name against the resolved extraction root, and Uti…
- CVE-2026-77301HIGHCVSS 7.5EG 7.5✓ Fixed in 0.6.12026-09-18
adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value ag…
Check whether adm-zip is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for adm-zip CVEs against the assets you own.
Start Free Scan →