{
  "@id": "urn:uuid:d31e12f6-a4cb-4811-8dc8-2868fcfa43eb",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 4,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-29T23:19:00.139552+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-1002204 is fixed in version 0.4.4-tuxcare.2 of adm-zip.",
      "vulnerability": {
        "name": "CVE-2018-1002204"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-0842 is a false positive for adm-zip 0.4.4-tuxcare.2. false_positive \u2014 CVE-2023-0842 is a wrong-project match. The advisory concerns xml2js (an XML parsing library), while the target repository is adm-zip version 0.4.4-tuxcare.1 (a ZIP compression library). These are completely different products with no code relationship.",
      "vulnerability": {
        "name": "CVE-2023-0842"
      },
      "impact_statement": "false_positive \u2014 CVE-2023-0842 is a wrong-project match. The advisory concerns xml2js (an XML parsing library), while the target repository is adm-zip version 0.4.4-tuxcare.1 (a ZIP compression library). These are completely different products with no code relationship."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-29T20:05:06.882388+00:00",
      "status_notes": "Vulnerability CVE-2026-102282 does not affect version 0.4.4-tuxcare.2 of adm-zip. not_affected \u2014 Version 0.4.4 predates the vulnerable feature entirely. The `keepOriginalPermission` parameter and `fileAttr` getter that enable the vulnerability were introduced in version 0.5.16+. In version 0.4.4, extraction methods (`extractAllTo`, `extractEntryTo`) never read or apply Unix permission bits from zip entries\u2014all extracted files receive default permissions (0o666). While external attributes a...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-102282"
      },
      "impact_statement": "not_affected \u2014 Version 0.4.4 predates the vulnerable feature entirely. The `keepOriginalPermission` parameter and `fileAttr` getter that enable the vulnerability were introduced in version 0.5.16+. In version 0.4.4, extraction methods (`extractAllTo`, `extractEntryTo`) never read or apply Unix permission bits from zip entries\u2014all extracted files receive default permissions (0o666). While external attributes a..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39244 is fixed in version 0.4.4-tuxcare.2 of adm-zip.",
      "vulnerability": {
        "name": "CVE-2026-39244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-77301 is fixed in version 0.4.4-tuxcare.2 of adm-zip.",
      "vulnerability": {
        "name": "CVE-2026-77301"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability GHSA-8238-w5pm-2374 affects version 0.4.4-tuxcare.2 of adm-zip.",
      "vulnerability": {
        "name": "GHSA-8238-w5pm-2374"
      },
      "action_statement": "Vulnerability GHSA-8238-w5pm-2374 affects version 0.4.4-tuxcare.2 of adm-zip."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability GHSA-c6fg-446q-cg94 affects version 0.4.4-tuxcare.2 of adm-zip.",
      "vulnerability": {
        "name": "GHSA-c6fg-446q-cg94"
      },
      "action_statement": "Vulnerability GHSA-c6fg-446q-cg94 affects version 0.4.4-tuxcare.2 of adm-zip."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability GHSA-p634-w6r4-rjp2 affects version 0.4.4-tuxcare.2 of adm-zip.",
      "vulnerability": {
        "name": "GHSA-p634-w6r4-rjp2"
      },
      "action_statement": "Vulnerability GHSA-p634-w6r4-rjp2 affects version 0.4.4-tuxcare.2 of adm-zip."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-29T18:46:58.638266+00:00",
      "status_notes": "Vulnerability GHSA-rcw4-f5rp-g42v affects version 0.4.4-tuxcare.2 of adm-zip.",
      "vulnerability": {
        "name": "GHSA-rcw4-f5rp-g42v"
      },
      "action_statement": "Vulnerability GHSA-rcw4-f5rp-g42v affects version 0.4.4-tuxcare.2 of adm-zip."
    }
  ]
}
