GHSA-p634-w6r4-rjp2
### Summary A ZIP file can contain two entries with the identical name. adm-zip keeps both in its internal entry list, but its name-lookup table only retains the last one written. `getEntry(name)` and `extractAllTo()` walk these two different internal structures, so they can each resolve a duplicate name to a *different* entry. An application that validates a named entry's contents via `getEntry()` before trusting an archive, then extracts the whole archive, can end up approving one file's content while a different file's bytes are what actually land on disk under that name. ### Details - `zipFile.js:58-83` retains both entries in `entryList` but overwrites `entryTable[name]` with only the last one written. - `adm-zip.js:83-95,658-663` uses `entryTable` for `getEntry()` lookups — returns the *last* duplicate. - `adm-zip.js:769-914` iterates `entryList` for extraction — writes the *first* duplicate (sync, default overwrite policy). ### PoC ```js const AdmZip = require('adm-zip'); const z = new AdmZip({ noSort: true }); z.addFile('a.txt', Buffer.from('FIRST')); z.addFile('b.txt', Buffer.from('SECOND')); const raw = Buffer.from(z.toBuffer()); // rename the a.txt entry to b.txt directly in the raw bytes for (let at = raw.indexOf('a.txt'); at >= 0; at = raw.indexOf('a.txt', at + 5)) { raw.write('b.txt', at); } const parsed = new AdmZip(raw, { noSort: true }); const validated = parsed.getEntry('b.txt').getData().toString(); parsed.extractAllTo(outDir, false); // validated === "SECOND", but the file written to disk === "FIRST" ``` Reproduced on the pinned commit (`2b4d84087d45344643e0183756e19191d52815cc`) ### Impact An application that checks a named entry's content before trusting an untrusted ZIP, then extracts it, can be made to approve different bytes than what actually gets written to disk — the classic check/use split that this kind of validate-then-extract pattern relies on.
Properties
- severity
- medium
- summary
- adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
- cvss_score
- 5.9
- retrieved_at
- 2026-09-30T02:27:15+00:00
- ghsa_published
- 2026-09-29T23:11:01Z
- source_url
- https://github.com/advisories/GHSA-p634-w6r4-rjp2
- ghsa_updated
- 2026-09-29T23:11:04Z
- ghsa_id
- GHSA-p634-w6r4-rjp2
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-p634-w6r4-rjp2
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- signal_observed_at
- 2026-09-30T02:27:15+00:00
- is_ghsa_only
- true
Related Entities (5)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph