
Archived
jsprime
a javascript static security analysis tool
code-analysiseducationstatic-analysis+2
595

CVE-2026-102282: adm-zip LPE via SUID/SGID preservation during archive extraction (fixed in 0.6.1)

Independent offline regression of CVE-2026-44431 across pinned urllib3 releases, with original reporter attribution.

Reverse engineering notes and a working PoC for the macOS PackageKit symlink-following bug (CVE-2026-28912), with disassembly diff of the 26.6 fix.