CVE-2026-107709: Bower decompress-zip has a path traversal vulnerability
A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in lib/decompress-zip.js improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bower decompress-zipto a version that resolves this vulnerability.Fixed in 0.3.3
Event History
Frequently Asked Questions
Which deployments are most exposed?
Applications using npm/decompress-zip through version 0.3.3 to extract ZIP archives are exposed when an attacker can influence archive contents and there are writable directories adjacent to the intended extraction directory.
What does an attacker need to exploit this issue?
The attacker needs to supply a crafted ZIP archive with entry paths that resolve into prefix-sibling directories. The impact depends on which files outside the extraction directory can be overwritten in the target environment.