mediumCVSS 5.9Vulnerability

GHSA-p634-w6r4-rjp2

### Summary A ZIP file can contain two entries with the identical name. adm-zip keeps both in its internal entry list, but its name-lookup table only retains the last one written. `getEntry(name)` and `extractAllTo()` walk these two different internal structures, so they can each resolve a duplicate name to a *different* entry. An application that validates a named entry's contents via `getEntry()` before trusting an archive, then extracts the whole archive, can end up approving one file's content while a different file's bytes are what actually land on disk under that name. ### Details - `zipFile.js:58-83` retains both entries in `entryList` but overwrites `entryTable[name]` with only the last one written. - `adm-zip.js:83-95,658-663` uses `entryTable` for `getEntry()` lookups — returns the *last* duplicate. - `adm-zip.js:769-914` iterates `entryList` for extraction — writes the *first* duplicate (sync, default overwrite policy). ### PoC ```js const AdmZip = require('adm-zip'); const z = new AdmZip({ noSort: true }); z.addFile('a.txt', Buffer.from('FIRST')); z.addFile('b.txt', Buffer.from('SECOND')); const raw = Buffer.from(z.toBuffer()); // rename the a.txt entry to b.txt directly in the raw bytes for (let at = raw.indexOf('a.txt'); at >= 0; at = raw.indexOf('a.txt', at + 5)) { raw.write('b.txt', at); } const parsed = new AdmZip(raw, { noSort: true }); const validated = parsed.getEntry('b.txt').getData().toString(); parsed.extractAllTo(outDir, false); // validated === "SECOND", but the file written to disk === "FIRST" ``` Reproduced on the pinned commit (`2b4d84087d45344643e0183756e19191d52815cc`) ### Impact An application that checks a named entry's content before trusting an untrusted ZIP, then extracts it, can be made to approve different bytes than what actually gets written to disk — the classic check/use split that this kind of validate-then-extract pattern relies on.

Properties

severity
medium
summary
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
cvss_score
5.9
retrieved_at
2026-09-30T02:27:15+00:00
ghsa_published
2026-09-29T23:11:01Z
source_url
https://github.com/advisories/GHSA-p634-w6r4-rjp2
ghsa_updated
2026-09-29T23:11:04Z
ghsa_id
GHSA-p634-w6r4-rjp2
last_source
GitHub Advisory Database
cve_id
GHSA-p634-w6r4-rjp2
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
signal_observed_at
2026-09-30T02:27:15+00:00
is_ghsa_only
true

Related Entities (5)

VULNERABLE_TO (1)

←[Software]npm/adm-zip

AFFECTS (1)

→[Software]npm/adm-zip

HAS_WEAKNESS (2)

→[Weakness]Interpretation Conflict
→[Weakness]Incorrect Behavior Order

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-p634-w6r4-rjp2 (CVSS 5.9) — Ninja Signal Threat Intelligence | Ninja Signal