CVE-2026-107709
Received Received - Intake

Path Traversal in Bower decompress-zip

Vulnerability report for CVE-2026-107709, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: CERT/CC

Description

A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Bower Decompress-Zip decompress-zip 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Bower decompress-zip through version 0.3.3. It occurs because the library improperly validates archive entry paths during ZIP extraction. A crafted ZIP file can trick the library into writing files outside the intended directory by using paths that share a prefix with the target directory, such as ../userdir-EVIL/x escaping /uploads/userdir.

Detection Guidance

Check if your system uses decompress-zip version 0.3.3 or earlier. Inspect ZIP extraction processes for unexpected file writes outside intended directories. Monitor for suspicious file creation in sibling paths sharing prefixes with extraction targets.

Impact Analysis

Exploitation may allow attackers to overwrite arbitrary files, modify application configurations, or execute malicious code on the system. Since the library silently writes files outside the intended directory without errors, it could lead to data corruption, denial of service, or full system compromise depending on the environment.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized file access or modification. For GDPR, it may lead to unauthorized data exposure or processing. For HIPAA, it could allow tampering with protected health information. Organizations using affected versions risk non-compliance due to insufficient file path validation.

Mitigation Strategies

Replace decompress-zip with a maintained alternative like yauzl. Validate entry paths using path.relative() before extraction. Extract files to isolated directories. Implement allow-list-based file movement. Avoid using versions ≀ 0.3.3.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107709. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart