Path Traversal Vulnerability in Bower Decompress-Zip Tool
CVE-2026-107709

Currently unrated

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107709?

A path traversal vulnerability exists in Bower's decompress-zip tool, affecting versions up to 0.3.3. This vulnerability arises from inadequate validation of archive entry paths when extracting ZIP files. An attacker can craft a malicious ZIP archive that contains entries designed to resolve to sibling directories, thereby enabling files to be written outside the designated extraction path. The exploitation of this flaw can result in arbitrary file overwrites or even compromise the application, potentially allowing remote code execution depending on the target environment's configuration and permissible write paths.

Affected Version(s)

decompress-zip 0 <= 0.3.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.