{
  "@id": "urn:uuid:9bf6b093-56c7-4ab5-83bc-69d992c75acd",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 4,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-29T23:19:00.139552+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.16-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.16-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-29T20:06:47.307068+00:00",
      "status_notes": "Vulnerability CVE-2026-102282 does not affect version 0.4.16-tuxcare.1 of adm-zip. not_affected \u2014 Version 0.4.16 is not affected by CVE-2026-102282. The vulnerability requires the `keepOriginalPermission` feature and `fileAttr` getter, which were introduced in commit 2b2a1d7 (September 2021). This commit is not in 0.4.16's ancestry. The target always extracts files with default permission 0o666, completely ignoring zip entry permission bits. The attack chain from zip attributes to files wit...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-102282"
      },
      "impact_statement": "not_affected \u2014 Version 0.4.16 is not affected by CVE-2026-102282. The vulnerability requires the `keepOriginalPermission` feature and `fileAttr` getter, which were introduced in commit 2b2a1d7 (September 2021). This commit is not in 0.4.16's ancestry. The target always extracts files with default permission 0o666, completely ignoring zip entry permission bits. The attack chain from zip attributes to files wit..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.16-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.16-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39244 is fixed in version 0.4.16-tuxcare.1 of adm-zip.",
      "vulnerability": {
        "name": "CVE-2026-39244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.16-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.16-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-77301 is fixed in version 0.4.16-tuxcare.1 of adm-zip.",
      "vulnerability": {
        "name": "CVE-2026-77301"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.16-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.16-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability GHSA-8238-w5pm-2374 affects version 0.4.16-tuxcare.1 of adm-zip.",
      "vulnerability": {
        "name": "GHSA-8238-w5pm-2374"
      },
      "action_statement": "Vulnerability GHSA-8238-w5pm-2374 affects version 0.4.16-tuxcare.1 of adm-zip."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.16-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.16-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability GHSA-c6fg-446q-cg94 affects version 0.4.16-tuxcare.1 of adm-zip.",
      "vulnerability": {
        "name": "GHSA-c6fg-446q-cg94"
      },
      "action_statement": "Vulnerability GHSA-c6fg-446q-cg94 affects version 0.4.16-tuxcare.1 of adm-zip."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.16-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.16-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability GHSA-p634-w6r4-rjp2 affects version 0.4.16-tuxcare.1 of adm-zip.",
      "vulnerability": {
        "name": "GHSA-p634-w6r4-rjp2"
      },
      "action_statement": "Vulnerability GHSA-p634-w6r4-rjp2 affects version 0.4.16-tuxcare.1 of adm-zip."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.16-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.16-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-29T18:46:58.638266+00:00",
      "status_notes": "Vulnerability GHSA-rcw4-f5rp-g42v affects version 0.4.16-tuxcare.1 of adm-zip.",
      "vulnerability": {
        "name": "GHSA-rcw4-f5rp-g42v"
      },
      "action_statement": "Vulnerability GHSA-rcw4-f5rp-g42v affects version 0.4.16-tuxcare.1 of adm-zip."
    }
  ]
}
