Bower decompress-zip has a path traversal vulnerability
Summary
| CVE | CVE-2026-107709 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-08 17:17:16 UTC |
| Updated | 2026-10-08 17:17:16 UTC |
| Description | A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths. |
Risk And Classification
Problem Types: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Bower Decompress-Zip | Decompress-zip | affected 0.3.3 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| moizxsec.github.io/writeups/decompress-zip-zip-slip-sibling-prefix-bypass | [email protected] | moizxsec.github.io | |
| github.com/bower/decompress-zip | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.