PatchSiren

cthackers CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cthackers CVE published 2026-09-29

CVE-2026-102282

CVE-2026-102282: The adm-zip library for Node.js did not properly handle Unix permission bits when extracting ZIP archives, allowing for local privilege escalation. This vulnerability, with a CVSS score of 7.1 and HIGH severity, can lead to potential local privilege escalation in environments like Docker builds, CI runners, and privileged install steps. Developers and administrators should verify and upda [truncated]

MEDIUM cthackers CVE published 2026-08-24

CVE-2026-76845

CVE-2026-76845 debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T14:17:02.423Z and has not been modified since then. The NVD entry is currently Deferred. Defenders responsible for systems or applications using adm-zip for extraction, especially in shared or predictable extraction directories, should assess exposure and prioritize verification and patching. The vulnera [truncated]

HIGH cthackers CVE published 2026-07-10

CVE-2026-39244

A denial of service vulnerability exists in adm-zip before version 0.5.18. The vulnerability occurs due to a manipulated uncompressed size header field in a crafted ZIP file, which can cause a memory allocation amplification ratio of over 33 million to 1. This can lead to an immediate process crash in applications that accept untrusted ZIP files via adm-zip. The vulnerability is caused by the lack of vali [truncated]