Description
A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths.
Published: 2026-10-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary file overwrite with potential remote code execution
Action: Apply Patch
AI Analysis

Impact

A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3 because the library inadequately validates entry paths in ZIP archives. A crafted archive with entries that resolve to sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths.

Affected Systems

The affected library is Bower Decompress‑Zip (decompress‑zip). Versions up to and including 0.3.3 are vulnerable. Any application importing this library for ZIP extraction is at risk if it processes untrusted ZIP files.

Risk and Exploitability

The vulnerability is not listed in CISA KEV, and EPSS data is not available, so historical exploitation data is unclear. However, the flaw permits write operations to arbitrary paths when supplied with crafted ZIP files. If the application can be tricked into extracting such a ZIP, an attacker may overwrite critical configuration or executable files, leading to remote code execution. The attack vector is inferred to be local or remote upload of a ZIP file that the application then extracts. The CVSS score is not provided, but the potential impact suggests a high severity assessment.

Generated by OpenCVE AI on October 8, 2026 at 18:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update decompress-zip to version 0.3.4 or newer.
  • Patch the library to reject entries that resolve outside the intended extraction directory (for example, strip or validate paths containing "../" or absolute paths).
  • Ensure extraction is performed in a sandboxed directory and enforce strict write permissions or whitelist path validation before writing files.

Generated by OpenCVE AI on October 8, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Thu, 08 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths.
Title Bower decompress-zip has a path traversal vulnerability
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-10-08T20:23:46.370Z

Reserved: 2026-10-08T16:57:51.188Z

Link: CVE-2026-107709

cve-icon Vulnrichment

Updated: 2026-10-08T20:23:42.560Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T17:17:16.293

Modified: 2026-10-08T21:17:52.420

Link: CVE-2026-107709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:00:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')