Impact
A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3 because the library inadequately validates entry paths in ZIP archives. A crafted archive with entries that resolve to sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths.
Affected Systems
The affected library is Bower Decompress‑Zip (decompress‑zip). Versions up to and including 0.3.3 are vulnerable. Any application importing this library for ZIP extraction is at risk if it processes untrusted ZIP files.
Risk and Exploitability
The vulnerability is not listed in CISA KEV, and EPSS data is not available, so historical exploitation data is unclear. However, the flaw permits write operations to arbitrary paths when supplied with crafted ZIP files. If the application can be tricked into extracting such a ZIP, an attacker may overwrite critical configuration or executable files, leading to remote code execution. The attack vector is inferred to be local or remote upload of a ZIP file that the application then extracts. The CVSS score is not provided, but the potential impact suggests a high severity assessment.
OpenCVE Enrichment